Best Vulnerability Scanner Software - Page 15

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 236

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,800+ Authentic Reviews
  • 236+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Orca Security, Tenable Nessus, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=orca-security&focus%5B%5D=tenable-nessus&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Secuna Response

SECUNA is the first and only Cybersecurity Testing Platform in the Philippines helping Startups and SMEs by connecting them to the most advanced and highly-vetted cybersecurity professionals in the world to simulate cyber-attacks and find security flaws that real-world malicious hackers can exploit and leverage to gain access to IT systems.

Who Is the Company Behind Secuna Response?

  • Seller: Secuna
  • Year Founded: 2017
  • HQ Location: Taguig, PH
  • LinkedIn® Page: www.linkedin.com
    23 employees on LinkedIn®

Securelic

Securelic is an open source powered vulnerability scanning and external attack surface discovery platform built for modern security teams. It helps organizations continuously identify internet facing assets, uncover security weaknesses across web applications, APIs, networks and SSL/TLS configurations and turn findings into clear, actionable security insight. Designed for teams that need visibility beyond occasional scans, Securelic brings multiple security engines together in one platform to support continuous monitoring, practical reporting and more confident security decision making.

Who Is the Company Behind Securelic?

SECURITY by HTTPCS

Detect security flaws in your website or web application and avoid being hacked. HTTPCS Security puts Machine Learning at the service of your cyber security to protect your site against hacking and data leaks.

Who Is the Company Behind SECURITY by HTTPCS?

  • Seller: HTTPCS by Ziwit
  • Year Founded: 2011
  • HQ Location: Montpellier, FR
  • Twitter: @httpcs
    2,812 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

SecurityMetrics HIPAA Compliance Solutions

SecurityMetrics helps you identify which HIPAA requirements apply to your organization and guides you through HIPAA compliance. SecurityMetrics unmatched support helps you every step of the way on your path towards HIPAA compliance. When you partner with SecurityMetrics, you will love our detailed work and world-class support.

Who Is the Company Behind SecurityMetrics HIPAA Compliance Solutions?

  • Seller: SecurityMetrics
  • Year Founded: 2000
  • HQ Location: Orem, Utah, United States
  • Twitter: @SecurityMetrics
    3,757 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    288 employees on LinkedIn®

Skilled Scan

SkilledScan is an advanced vulnerability scanning service that uses the latest technology to identify potential security weaknesses in your website. Our expert team provides you with a comprehensive technical report and executive summary, explaining any vulnerabilities in simple language so that you can easily understand the issues and take appropriate action while keeping everything affordable

Who Is the Company Behind Skilled Scan?

The Columbus Collaboratory Vulnerability Management Solution

The Columbus Collaboratory Vulnerability Management Solution provides a 360-degree, single-console view via a managed service that helps organizations make informed business decisions and mitigate threats. Rather than staff an expensive threat-intelligence team, the Columbus Collaboratory Vulnerability Management Solution affordably delivers the knowledge, recommendations, and service of a threat-smart team. The Columbus Vulnerability Management Solution features allow you to: • Access Trending Threats: Maintain ongoing situational awareness of threats as they relate to known vulnerabilities through trending threats and CVE® (common vulnerability exposures) lists. • Break Down Vulnerabilities: Effectively understand your vulnerabilities by an asset, by application, and by scan— as well as how they map to frameworks, from something granular like CWE™ (common weakness enumeration), to something as specific as MITRE ATT&CK™ and NIST. • Ingest Scheduled Scans: Generated reports allow you to frequently and continuously monitor changes. • Manage Exceptions: Discover what host, application, and vulnerability-type exceptions are expiring by tracking and reporting capabilities. Your team can resolve tracked exceptions through data cleaning, maintenance, and mitigations. • Monitor Your Risk Score: Evaluate your vulnerabilities, discovered assets, and applications based on an assigned risk score. • Perform Custom Tagging: Tailor your filtering and reporting with host, application, and vulnerability tagging. • Run Analytics and Visualizations: Immediately access easy-to-reference charts and graphs that communicate your organizational security posture. Compare scan data to track progress and new changes. • Tap Into Our Security Expertise: We manage your external and/or internal scanning needs and provide expert analysis on prioritization, as well as convey this to your leadership team(s) through progress templates.

Who Is the Company Behind The Columbus Collaboratory Vulnerability Management Solution?

Topscan

Topscan is a continuous security monitoring platform for the DevOps engineer or CTO who owns security among other things. It covers the whole delivery pipeline in one subscription — static analysis in your code, dynamic scanning of live applications and infrastructure, and continuous monitoring of everything you expose to the internet — instead of three separate vendors for SAST, DAST and attack surface management. Perimeter. External infrastructure scanning reports open ports, service versions and known server vulnerabilities matched against CVE databases, with unlimited scheduled rescans. Asset discovery maps the subdomains and hosts you forgot about — the Grafana, the Sentry, the staging box nobody remembers deploying — and new hosts arrive with a review prompt: you confirm ownership before anything is scanned. Attack surface monitoring keeps every exposed service inventoried, and certificate watch catches TLS/SSL expiry weeks early instead of on the Friday night it happens. Applications and code. Web application scanning runs OWASP-class checks against live apps: SQL injection, XSS, exposed admin panels, default credentials, missing headers. Static application security testing covers three kinds of risk in one scan — vulnerable code patterns, committed secrets and keys, and known CVEs in dependencies (software composition analysis) — on every commit, pointing at the exact file and line. Pipeline and cloud. A CI/CD webhook gives you a unique event link to call from the last step of your deploy script: no API keys, no agent, nothing installed on your servers. AWS connects with keys you issue to discover EC2 and Route 53 resources, which are added to monitoring and rescanned when they change. Workflow. Findings are deduplicated and carry severity in your context, CVSS, a first-seen date and an SLA clock with overdue flags. Snooze what you accept, mark false positives and they stop resurfacing, and work through a large backlog in triage mode. Informational findings stay out of the feed and never touch your score. One security score tracks the whole estate over time — the number you show yourself, your CEO or an auditor. Alerts reach the team in Slack or Microsoft Teams and turn into Jira tickets; chat and tracker routing starts on the Advanced plan. Audit and compliance. Auditors ask for evidence of regular scanning and an inventory of what is exposed: scan history with downloadable reports and an exportable asset inventory answer both, which is what most teams use Topscan for ahead of SOC 2, ISO 27001 or a customer security review. Auditor seats are free and read-only, and users are unlimited on every plan. Pricing starts at $129 per month and is published on the site — no demo call required to see it — with a 14-day free trial of the full plan and no credit card. Add a domain and the first map of your perimeter arrives in five to ten minutes.

Who Is the Company Behind Topscan?

  • Seller: Topscan
  • Year Founded: 2024
  • HQ Location: Dubai, AE
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Trickest Platform

Trickest provides an innovative approach to offensive cybersecurity automation, assets, and vulnerability discovery. The platform combines extensive adversary tactics and techniques with full transparency, hypercustomization, and hyperscalability, making it the go-to platform for offensive security operations. The Trickest platform comes with comprehensive tooling, scripting, managed infrastructure, scaling, ready-to-go solutions, and analytics, serving as a collaborative command center for Offensive Security, Penetration testing, Red teams, Security Analysts, and Security Service providers (MSSPs). What makes us different? Easy customization of logic, inputs, outputs, and integrations, making them adaptable to specific needs and thus producing superior-quality data compared to others. Some of the automation workflows and solutions that our customers deploy and execute: - Attack Surface Discovery - Vulnerability Scanning - Dynamic Application Security Testing (DAST) - Recon/Information Gathering (Passive & Active) - Organization OSINT - CVE scanning - Cloud Scanning - DNS recon & research - Subdomain Enumeration - Subdomain Takeover - Custom Security Automation and Orchestration Main components of the Trickest platform include: Solutions & Analytics - Ready-to-go and transparent solutions for Attack Surface Discovery, Vulnerability Scanning, Dynamic Application Security Testing (DAST), and Open-source intelligence OSINT, offering insight into every step of the process, easy customization, and Analytics on the top. The Builder - Access to 90+ workflow templates, 300+ open-source tools, Bash & Python scripting, CLI for building custom workflows to discover asset, vulnerabilities, scan network & apps, crawl, spider, enumerate, fuzz, bruteforce and much more. Hyperscalability - Whether scanning regional infrastructures with 100s of 1000s of assets or smaller organizational scopes, Trickest supports it all without per-asset costs.

Who Is the Company Behind Trickest Platform?

  • Seller: Trickest
  • Year Founded: 2020
  • HQ Location: Dover, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Vuln0x

Vuln0x is developed by Solustiq Yazılım ve Yapay Zeka Teknolojileri A.Ş., an AI-driven software company headquartered in Edirne, Turkey, with international operations through Tech In Wise IT Solutions L.L.C. in Dubai. Solustiq specializes in building AI-powered SaaS products across security, market research, and developer tooling. Vuln0x is the company's dedicated security platform, built from the ground up to make professional-grade penetration testing accessible to teams of any size. Vuln0x combines automated vulnerability scanning with Sentinel, an autonomous AI penetration testing agent that orchestrates 29+ Kali Linux security tools through a chat interface. Sentinel follows a 7-phase attack methodology covering reconnaissance, surface analysis, CMS detection, parameter discovery, injection testing, authentication testing, and report generation. It scans using 5,800+ Nuclei templates, adapts to WAF detection, chains findings into deeper analysis, and delivers structured reports with severity ratings and remediation steps. Additional capabilities include scheduled scans for continuous monitoring, a risk scoring dashboard, API and CI/CD integration, and professional PDF reporting all with zero setup required. Vuln0x solves a critical gap for SMBs, digital agencies, and DevSecOps teams: getting pentest-grade security results without the pentest-grade cost and complexity. Traditional penetration testing requires expensive consultants and days of manual work. Automated scanners catch surface-level issues but miss chained vulnerabilities. Vuln0x bridges both Sentinel thinks like a pentester, acts autonomously, and reports like a professional, so teams can ship secure applications without slowing down development or breaking the budget.

Who Is the Company Behind Vuln0x?

VulnCheck For Government

VulnCheck for Government is a specialized cybersecurity solution designed to empower government agencies with advanced tools and intelligence to proactively identify, assess, and mitigate vulnerabilities. By providing comprehensive exploit and vulnerability intelligence, initial access intelligence, and IP intelligence, VulnCheck enables agencies to enhance their cyber defense strategies and stay ahead of emerging threats.

Who Is the Company Behind VulnCheck For Government?

  • Seller: VulnCheck
  • Year Founded: 2021
  • HQ Location: Lexington, US
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®
Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026