getapp-logo

App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. 

Top Rated Vulnerability Scanner Software with Free - Page 2

Last updated: September 2026

1 filter applied

Features


Integrated with


Pricing model


Devices supported


Organization types


User rating


48 software options

OX Security logo

Cloud-security solution for administrators.

learn more
OX Security is a cloud security platform that helps small to large businesses in technology, banking, financial services, and other sectors protect their organization from advanced cyber threats. The platform provides real-time threat detection and response capabilities, giving administrators the ability to gain insights into their network so they can identify and address threats before those threats cause damage.

Read more about OX Security

Users also considered
Gordon VAPT logo

Automated vuln scanning & penetration testing

learn more
VAPT platform that identifies, validates, and prioritizes vulnerabilities across web, API, cloud, and network environments using automated scanning and expert testing, with actionable remediation guidance and continuous monitoring to reduce risk.

Read more about Gordon VAPT

Users also considered
CVEFinder logo

Website scanner for CVEs and dependencies

learn more
CVEFinder.io is a vulnerability scanner that identifies known Common Vulnerabilities and Exposures and vulnerable dependencies on websites. The platform analyzes headers, HTML, JavaScript, and package.json files to detect technologies and npm packages with security issues. It provides single and bulk scanning capabilities, technology detection with confidence levels, and access to a database of over three hundred forty-three thousand CVEs across nearly two hundred thousand products.

Read more about CVEFinder

Users also considered
Praetorian Guard logo

Continuous offensive security

learn more
Continuous offensive security. Agentic AI plus the top 1% of offensive operators. Attacker-verified.

Read more about Praetorian Guard

Users also considered
BugProve logo

Product Security Simplified for the Internet of Things

learn more
BugProve offers an automated firmware analysis tool to identify, remediate and monitor known and zero-day vulnerabilities in IoT products - such as vulnerable dependencies, coding mistakes, misconfiguration, and more. Get your first results within 5 minutes and export your findings via links or PDF.

Read more about BugProve

Users also considered
Defendify logo

All-in-one cybersecurity platform

learn more
Defendify offers comprehensive cybersecurity protection with layers of security including threat detection, security awareness training, assessments, and incident response support. Backed by automation and expert guidance, the platform aims to strengthen security posture across people, processes, and technology.

Read more about Defendify

Users also considered
Vulseek logo

Attack surface and vulnerability management

learn more
Vulseek is a modern attack surface management and vulnerability detection platform designed for small and medium-sized organizations. It combines external scanning, internal network visibility, and cross-platform endpoint agents to give teams complete insights

Read more about Vulseek

Users also considered
Burp Suite Professional logo

Secure web apps with advanced testing tools.

learn more
Industry-leading toolkit for web security testing to find, exploit, and validate vulnerabilities in web apps and APIs.

Read more about Burp Suite Professional

Users also considered
Sensagraph logo

Agentless vulnerability scanning in minutes.

learn more
Sensagraph is an agentless external security scanner that shows what your site exposes to the internet. In one pass it finds vulnerabilities like SQL injection and XSS, weak TLS, open ports, and risky tech, then gives risk-ranked, client-ready reports. Built for agencies, founders, and solo devs.

Read more about Sensagraph

Users also considered
Edgewatch logo

External attack surface management platform

learn more
Edgewatch attack surface management platform assists companies with discovering, monitoring, and analyzing devices accessible from the Internet.

Read more about Edgewatch

Users also considered
Enzoic for Active Directory logo

Tool to stop breached passwords & credentials automatically

learn more
Enzoic for Active Directory is a software that helps automate password security, block weak and exposed credentials in real time, enforce NIST compliance, and protect the organization without user disruption.

Read more about Enzoic for Active Directory

Users also considered
Fairwinds Insights logo

Configuration validation for Kubernetes workloads

learn more
Fairwinds Insights delivers dev and ops teams shared visibility across multi-clusters, anticipating and remediating configuration and security threats before they cost time or money.

Read more about Fairwinds Insights

Users also considered
CloudSploit logo

Automated security and configuration monitoring for AWS

learn more
CloudSploit is an automated security and configuration monitoring tool for Amazon Web Services (AWS) which scans configurations, looking for security concerns

Read more about CloudSploit

Users also considered
Insight Recon logo

AD security assessment and remediation tool

learn more
Insight Recon is an Active Directory security tool that performs read-only scans on domain controllers to identify vulnerabilities and misconfigurations. It conducts over 135 security checks covering identity accounts, privileged access, certificate services, Kerberos delegation, and Group Policy settings. Each finding includes attacker context explaining exploitation techniques and provides PowerShell-level remediation steps tailored to the environment.

Read more about Insight Recon

Users also considered
CyberSmart logo

Cybersecurity, automated compliance, GDPR readiness for SMBs

learn more
CyberSmart is a cybersecurity solution that identifies system vulnerabilities on all devices, helps prevent cyberattacks, and provides continuous compliance while preparing for IASME Certification. This solution provides 24/7 device monitoring, vulnerability scanning, remote auditing, and more.

Read more about CyberSmart

Users also considered
RoboShadow logo

Global Vulnerability Scanner. Cyber Security, Demystified.

learn more
Get a complete Internal & External Vulnerability Assessment for Free for your organisation or network. The RoboShadow Vulnerability Scanner platform give you all the main Cyber Security assessment tests that are common in Penetration Testing, Cyber Certifications and used by bad guys themselves.

Read more about RoboShadow

Users also considered
Trend Micro Cloud One logo

Cloud and cybersecurity software

learn more
Trend Micro Cloud One is cloud and cybersecurity software that helps businesses manage security policies, detect threats, receive malicious activity alerts, conduct root-cause analysis, and more from within a unified platform. It allows staff members to set up runtime container protection, manage security policies across multi-cloud environments, conduct health checks, and generate compliance reports, among other operations.

Read more about Trend Micro Cloud One

Users also considered
Vulnara logo

Cloud-based vulnerability management platform

learn more
Vulnara is a vulnerability management platform designed to help businesses identify, track, and remediate security risks across their.

Read more about Vulnara

Users also considered
Ostorlab logo

Cloud-based vulnerability management platform

learn more
Ostorlab is a cloud-based vulnerability management platform designed to help businesses detect, monitor, and remediate risks across enterprises' external attack surfaces.

Read more about Ostorlab

Users also considered
AquilaX logo

AI-enabled security solution for developers

learn more
AquilaX provides AI-enabled security scanning for developers, supporting GitHub, GitLab, and Bitbucket repositories. With SecuriTron, their AI assistant, users can automate scan setup and identify vulnerabilities through both automated and tailored scans.

Read more about AquilaX

Users also considered
Axix VulnScan logo

AI-driven automated penetration testing & vulnerability scan

learn more
Axix Pentestagent is an AI-driven pentesting platform with continuous vulnerability scanning, simulated attack exploitation, and network mapping. Built with API access and remediation reporting, it automates penetration testing across networks and web applications.

Read more about Axix VulnScan

Users also considered
AppTotal logo

Vulnerability management software

learn more
AppTotal is a business applications security platform. It lets employees connect the apps & add-ons to IT-approved platforms without worrying about security. AppTotal streamlines third-party app vetting processes, maps and analyzes the apps and integrations already connected to your environment, and helps teams automate app and extensions recertification and off-boarding process across Office 365, Google Workspace, Atlassian, Slack and other major platforms.

Read more about AppTotal

Users also considered
HostedScan logo

Cloud-based vulnerability scanning and risk management tool

learn more
Designed for businesses of all sizes, HostedScan is a cloud-based vulnerability scanner solution that helps businesses monitor risk insights and generate screening reports accordingly.

Read more about HostedScan

Users also considered