getapp-logo

App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. 

Top Rated Vulnerability Scanner Software with Web based - Page 4

Last updated: September 2026

1 filter applied

Features


Integrated with


Pricing model


Devices supported


Organization types


User rating


121 software options

HTTPCS Security logo

Next-Gen Vulnerability Scanner for websites and web apps

learn more
HTTPCS Security protects your websites against hackers by detecting vulnerabilities that could be exploited and helping you to fix them.

Read more about HTTPCS Security

Users also considered
Crashtest Security logo

Cloud-based vulnerability scanning & testing software

learn more
Crashtest Security is a vulnerability testing software that helps businesses perform automated scans to detect cybersecurity threats across applications. Managers can conduct single-page, multi-page, and documentation-based scans to identify attack vectors across several web applications.

Read more about Crashtest Security

Users also considered
DeepSurface logo

Risk-based predictive vulnerability management platform

learn more
DeepSurface is a risk-based predictive vulnerability management platform for cybersecurity, delivering critical insights and actionable recommendations to the most vulnerable assets. It uses machine learning to detect vulnerabilities, provide prioritization, and manage critical patching—without causing disruption.

Read more about DeepSurface

Users also considered
CVEFinder logo

Website scanner for CVEs and dependencies

learn more
CVEFinder.io is a vulnerability scanner that identifies known Common Vulnerabilities and Exposures and vulnerable dependencies on websites. The platform analyzes headers, HTML, JavaScript, and package.json files to detect technologies and npm packages with security issues. It provides single and bulk scanning capabilities, technology detection with confidence levels, and access to a database of over three hundred forty-three thousand CVEs across nearly two hundred thousand products.

Read more about CVEFinder

Users also considered
Threatspy logo

Reinventing Application Security

learn more
Developer-first Application & API Security Management Platform

Read more about Threatspy

Users also considered
Praetorian Guard logo

Continuous offensive security

learn more
Continuous offensive security. Agentic AI plus the top 1% of offensive operators. Attacker-verified.

Read more about Praetorian Guard

Users also considered
BugProve logo

Product Security Simplified for the Internet of Things

learn more
BugProve offers an automated firmware analysis tool to identify, remediate and monitor known and zero-day vulnerabilities in IoT products - such as vulnerable dependencies, coding mistakes, misconfiguration, and more. Get your first results within 5 minutes and export your findings via links or PDF.

Read more about BugProve

Users also considered
blacklens.io logo

Discover vulnerabilities before attackers do.

learn more
Blacklensio is a platform that combines advanced penetration testing with proactive techniques like darknet monitoring, attack surface management, and vulnerability scanning to identify potential attack vectors early. By taking this comprehensive approach, it aims to not only detect costly cyber incidents but actively prevent them.

Read more about blacklens.io

Users also considered
BitNinja logo

A server security suite that detects & blocks web attacks

learn more
BitNinja is a cloud-based security suite designed to protect servers from botnets, scans, and other types of web attacks. Hosting providers can use the BitNinja defense network to detect and block botnet attacks. Features include real-time IP reputation, DoS detection, malware detection, and more. By analyzing all newly added rules, BitNinja aims to provide a low false-positive rate.

Read more about BitNinja

Users also considered
AlienVault OSSIM logo

Open source SIEM software

learn more
AlienVault OSSIM is a open source security information and event management (SIEM) software.

Read more about AlienVault OSSIM

Users also considered
StorageGuard logo

Your data isn’t secure, unless your storage & backup are.

learn more
The industry’s ONLY Vulnerability Scanner for enterprise storage & backup systems, helping to secure these systems to protect your data

Read more about StorageGuard

Users also considered
Defendify logo

All-in-one cybersecurity platform

learn more
Defendify offers comprehensive cybersecurity protection with layers of security including threat detection, security awareness training, assessments, and incident response support. Backed by automation and expert guidance, the platform aims to strengthen security posture across people, processes, and technology.

Read more about Defendify

Users also considered
Vulseek logo

Attack surface and vulnerability management

learn more
Vulseek is a modern attack surface management and vulnerability detection platform designed for small and medium-sized organizations. It combines external scanning, internal network visibility, and cross-platform endpoint agents to give teams complete insights

Read more about Vulseek

Users also considered
Secyour Enterprise logo

Securing every aspect of your online presence

learn more
Penetration testing and cybersecurity platform designed to help businesses monitor and protect their online presence across the web.

Read more about Secyour Enterprise

Users also considered
Sensagraph logo

Agentless vulnerability scanning in minutes.

learn more
Sensagraph is an agentless external security scanner that shows what your site exposes to the internet. In one pass it finds vulnerabilities like SQL injection and XSS, weak TLS, open ports, and risky tech, then gives risk-ranked, client-ready reports. Built for agencies, founders, and solo devs.

Read more about Sensagraph

Users also considered
Feroot logo

Cybersecurity solution

learn more
Feroot is a GRC AI platform that helps businesses automate website security and compliance programs to meet the requirements of PCI DSS 4.0, HIPAA, CCPA/CPRA, CIPA, GDPR, and other laws and standards. The platform provides complete visibility and control over a website's data, enabling businesses to stay ahead of evolving privacy compliance violations and security threats.

Read more about Feroot

Users also considered
Edgewatch logo

External attack surface management platform

learn more
Edgewatch attack surface management platform assists companies with discovering, monitoring, and analyzing devices accessible from the Internet.

Read more about Edgewatch

Users also considered
Deepinfo Attack Surface Platform logo

Know your attack surface. Empower your security.

learn more
Deepinfo Attack Surface Platform discovers all your digital assets, monitors them 24/7, detects any issues, and notifies you quickly so you can take immediate action.

Read more about Deepinfo Attack Surface Platform

Users also considered
Gearset DevOps logo

Cloud-based Salesforce DevOps platform for all teams

learn more
Cloud-based Salesforce DevOps platform covering CI/CD, metadata and data deployments, automated testing, backup, and version control.

Read more about Gearset DevOps

Users also considered
Tenable Vulnerability Management logo

Cloud and container security software

learn more
Tenable.io is a container security software that helps businesses assess vulnerabilities, prioritize remediation actions, monitor assets, and more on a centralized platform. The automated inspection module enables staff members to detect malware, handle hierarchy intelligence, and assess container images by layer.

Read more about Tenable Vulnerability Management

Users also considered
HTTPCS Cyber Vigilance logo

Data leaks monitoring and cyber threats detection solution

learn more
Cybervigilance is a semi-automated, cloud-based OSINT and Cyber Threat Intelligence (CTI) solution that monitors the web, deep web and darknet for information leaks and indications of cyber threats, and alerts you 24/7 before the incident occurs.

Read more about HTTPCS Cyber Vigilance

Users also considered
Topscan logo

Automated security scanning for servers and APIs

learn more
TopScan is a security scanning platform that automatically detects vulnerabilities in servers, libraries, and APIs. The solution offers continuous monitoring, attack surface discovery, and vulnerability management capabilities using open-source scanning engines such as OWASP ZAP and Nuclei. TopScan includes features for web application security, cloud security, static code analysis, and SSL/TLS certificate monitoring, with integration options for CI/CD pipelines and Slack notifications.

Read more about Topscan

Users also considered
Cyberwatch Vulnerability Manager logo

Vulnerability and asset inventory management software

learn more
Cyberwatch Vulnerability Manager is a security solution designed to help organizations track and manage vulnerabilities across network equipment, servers, devices, websites, workstations, and docker images via a unified portal. The platform lets users maintain an inventory of technologies and automatically captures and stores details about system issues, detection history, and remediation date.

Read more about Cyberwatch Vulnerability Manager

Users also considered
Amazon Inspector logo

Vulnerability Management for EC2 and ECR.

learn more
Amazon Inspector is a vulnerability management solution that helps businesses scan AWS workloads to expose and identify vulnerabilities, enhance the security and compliance of applications across AWS, and meet compliance requirements.

Read more about Amazon Inspector

Users also considered
Fairwinds Insights logo

Configuration validation for Kubernetes workloads

learn more
Fairwinds Insights delivers dev and ops teams shared visibility across multi-clusters, anticipating and remediating configuration and security threats before they cost time or money.

Read more about Fairwinds Insights

Users also considered