Vulnerability Management: 15 Tools compared
Vulnerability scanning and management platforms for identifying, prioritizing, and remediating security weaknesses. Compare enterprise, cloud, and open-source vulnerability management tools.
15 Vulnerability Management Tools, side by side
Ordered by reader upvotes, then A to Z.
| Tool | Deployment | Pricing model | Open source | Standards / certs |
|---|---|---|---|---|
| CVETodo | Cloud | Freemium; monthly or annual subscription | — | — |
| GuardNest | Cloud | Subscription | — | CREST, CHECK, ISO 27001 |
| RoboShadow | Cloud | Freemium with a paid subscription tier priced per account plus per-agent overage, and a quoted enterprise tier | — | SOC 2 Type II (vendor-stated, March 2026), Cyber Essentials Plus (vendor-stated), Annual CREST-certified penetration test (vendor-stated) |
| Arctic Wolf | Cloud | Per-asset managed service (annual contract) | — | — |
| Codename Sonar | Cloud | Freemium subscription | — | — |
| CrowdStrike Falcon Spotlight | Cloud | Per-endpoint (annual subscription, bundled with Falcon) | — | — |
| Greenbone OpenVAS | Self-hosted | Open source with commercial appliance options | Yes | ISO 27001 |
| KUMO | Self-hosted | Open Source | Yes | — |
| Microsoft Defender Vulnerability Management | Cloud | Per-user (monthly subscription, bundled with Microsoft 365 E5) | — | — |
| Nuclei | Cloud + Self-hosted | Open source with optional cloud platform | Yes | — |
| Qualys VMDR | Cloud | Per-asset (annual subscription) | — | FedRAMP, ISO 27001, SOC 2 Type II |
| Rapid7 InsightVM | Cloud + Self-hosted | Per-asset (monthly or annual subscription) | — | — |
| Tanium | Cloud + Self-hosted | Per-endpoint (annual enterprise license) | — | — |
| Tenable | Cloud | Per-asset (annual subscription) | — | — |
| Trivy | Self-hosted | Open source with commercial Aqua Platform | Yes | — |
Arctic Wolf
Managed Security Service ProvidersOrganizations without in-house security expertise wanting fully managed vulnerability scanning and prioritized remediation guidance
Arctic Wolf is a managed security operations platform that includes managed vulnerability management as part of its Concierge Security approach. Rather than providing a self-service vulnerability scanning tool, Arctic Wolf assigns dedicated security engineers (the Concierge Security Team) who configure, run, and interpret vulnerability scans on the customer's behalf, delivering prioritized remediation guidance. This managed approach targets organizations that lack in-house vulnerability management expertise and want a turnkey service rather than a platform they must operate themselves.
Codename Sonar
Vulnerability ManagementSmall security teams and consultants who want low cost, web based scans of hosts they own or are authorised to test.
Codename Sonar is a web based reconnaissance service from Artisan Technical Computer Services, LLC, positioned for blue team work and authorised penetration testing. Users enter an IP address or web address and choose a scan profile, ranging from a ping sweep and a top 20 TCP port quick scan to intense, comprehensive, web recon, stealth and Kali recon profiles. Optional modules cover traceroute, reverse DNS, version detection, OS fingerprinting, TLS inspection, OpenVAS NVT tests, UDP probes and an analyst briefing. The Pro plan adds SIEM, CSV, PDF and STIX 2.1 exports, a watchlist and asset inventory, certificate expiry monitoring and mapping to PCI DSS 4.0, ISO 27001, SOC 2 and HIPAA. The terms of service require users to own each target or hold express, current, written authorisation to test it. An M5Stack companion device for 2.4 GHz WiFi scanning is in alpha testing.
CrowdStrike Falcon Spotlight
Vulnerability ManagementCrowdStrike Falcon customers wanting vulnerability visibility without deploying additional scanning infrastructure
CrowdStrike Falcon Spotlight is an EDR-integrated vulnerability assessment module built on the CrowdStrike Falcon platform. Unlike traditional vulnerability scanners, Spotlight leverages the existing Falcon agent already deployed for endpoint detection and response, providing scanless vulnerability assessment that continuously evaluates endpoints for vulnerabilities without running network scans or requiring additional agents. This approach eliminates scanning overhead, provides real-time vulnerability data, and ties vulnerability context directly to threat intelligence.
CVETodo
Vulnerability ManagementSmall teams and MSPs that want CVE alerting tied to a live software inventory without an enterprise scanner
CVETodo aggregates CVE data into a browsable database with real-time tracking and alerting. Listings carry AI analyst deep dives, remediation priority scoring, and exploit and patch status, with CISA Known Exploited Vulnerabilities tracked and a Critical Patch Now ranking ordered by remediation priority. Alongside the database it offers an open-source inventory agent for servers, agentless appliance inventory for firewalls and VPN gateways, repository scanning for dependencies, an SBOM grading tool, and remediation reports with SLA aging, benchmarked against PCI DSS, Cyber Essentials and Essential Eight. Browsing the CVE database needs no account; tracking and alerting are paid. CVETodo is an independent New Zealand business, built and run from Tauranga, founded by Anthony Walker.
Greenbone OpenVAS
Vulnerability ManagementSecurity teams wanting a free, open-source vulnerability scanner with no licensing costs and full customization control
Greenbone OpenVAS (Open Vulnerability Assessment Scanner) is the world's most widely used open-source vulnerability scanner, maintained by Greenbone Networks. OpenVAS provides a comprehensive vulnerability testing framework with over 100,000 network vulnerability tests (NVTs), covering CVEs, misconfigurations, and security policy violations. As the open-source foundation of Greenbone's commercial Enterprise appliances, OpenVAS gives organizations a free, transparent, and community-driven vulnerability scanning engine that can be self-hosted and customized without licensing costs.
GuardNest
Vulnerability ManagementOrganisations using WorkNest Secure for penetration testing who want continuous scanning, live reporting, and retesting in the same platform
GuardNest is the client platform of WorkNest Secure, the cyber security division of WorkNest that brought Pentest People, Bulletproof, and Target Defense together under one brand in May 2026. It succeeds the SecurePortal platform Pentest People was known for, and serves two purposes: delivering penetration testing engagements, with live reports, direct chat to the consultant doing the work, and remediation tracking, and running continuous vulnerability management between tests through scheduled external and web application scanning. The platform includes a threat intelligence feed, security e-learning, and integrations with Jira, Slack, and Azure so findings flow into existing ticketing and collaboration tools. It is offered in tiers: a free Essentials tier, a Core tier listed at 1,000 GBP a year covering weekly scanning of up to 50 IPs, and Advanced and Pro tiers priced on application. WorkNest Secure itself is a CREST-accredited and NCSC CHECK Green Light penetration testing provider, so GuardNest sits alongside human-led testing rather than replacing it. It suits UK organisations that already use or are considering WorkNest Secure for testing and want scanning, reporting, and retesting in one place, and is less relevant to teams looking for a standalone enterprise vulnerability management suite with agent-based internal scanning.
KUMO
Vulnerability ManagementSecurity researchers and pentesters who want fast, free domain reconnaissance from the command line.
KUMO is an open-source (MIT-licensed) domain reconnaissance and OSINT framework, run from the command line or a local web UI. Given a domain, it runs 26 parallel modules covering DNS enumeration, subdomain discovery (passive and active), port scanning across 70+ ports, SSL/TLS certificate inspection, HTTP security header grading, sensitive endpoint discovery, vulnerability checks (150+ built-in signatures, CVE matching), leaked-credential and breach-data lookups, and JavaScript secret scanning. It pulls from free OSINT sources (crt.sh, Shodan InternetDB, HaveIBeenPwned, Wayback Machine, AlienVault OTX, and others) out of the box, with optional paid API keys (Shodan, Censys, Chiasmodon) for deeper coverage.
Microsoft Defender Vulnerability Management
Vulnerability ManagementMicrosoft-centric organizations wanting vulnerability management bundled with their existing Defender for Endpoint deployment
Microsoft Defender Vulnerability Management is Microsoft's built-in vulnerability assessment and management solution integrated into the Microsoft Defender for Endpoint platform. It provides continuous vulnerability discovery, risk-based prioritization, and remediation tracking across Windows, macOS, Linux, iOS, and Android endpoints. Leveraging the Defender for Endpoint agent already deployed in Microsoft environments, it delivers vulnerability visibility, security baseline assessment, and browser extension inventory without additional scanning infrastructure.
Nuclei
Vulnerability ManagementSecurity teams and researchers wanting a fast, customizable, template-driven vulnerability scanner for web and infrastructure testing
Nuclei is a fast, template-based open-source vulnerability scanner developed by ProjectDiscovery. Built in Go for high performance, Nuclei uses YAML-based templates to define and execute vulnerability checks across web applications, networks, DNS, cloud services, and more. With over 8,000 community-contributed templates covering CVEs, misconfigurations, exposed panels, default credentials, and technology detection, Nuclei has become the preferred tool for security researchers, bug bounty hunters, and organizations wanting a highly customizable and extensible scanning engine.
Qualys VMDR
Vulnerability ManagementOrganizations wanting an all-in-one cloud-based VM platform with integrated patching and asset inventory
Qualys VMDR (Vulnerability Management, Detection and Response) is a cloud-native vulnerability management platform that provides end-to-end visibility, detection, prioritization, and remediation of vulnerabilities across hybrid IT environments. Built on the Qualys Cloud Platform, VMDR combines asset inventory, vulnerability detection, threat intelligence-driven prioritization, and integrated patch management into a single workflow, enabling security teams to move from vulnerability discovery to remediation without switching tools.
Rapid7 InsightVM
Vulnerability ManagementOrganizations wanting risk-based VM with strong remediation tracking and integration across the Rapid7 Insight platform
Rapid7 InsightVM is a risk-based vulnerability management platform that combines live vulnerability assessment, real-time endpoint analytics, and risk-prioritized remediation workflows into the broader Rapid7 Insight platform. InsightVM uses the Rapid7 Insight Agent and scan engine to provide continuous visibility into vulnerabilities across on-premises, cloud, and remote assets, with real-time dashboards and remediation project tracking that bridges the gap between security and IT operations teams.
RoboShadow
Vulnerability ManagementSmall and mid-sized organisations and MSPs running Microsoft-centric estates that want vulnerability scanning and automated third-party patching from a single console, with a usable free tier for evaluation.
RoboShadow is a cloud-hosted vulnerability management and attack surface platform operated by ROBO SHADOW LTD, a UK company registered at Companies House under number 10726476 and incorporated on 13 April 2017. The platform combines an external scanner for internet-facing IPs and websites, a LAN scanner for internal device discovery, a web application scanner and endpoint agents that report patch level, antivirus status, encryption and firewall state. The vendor states that its Cyber Heal AutoFix function patches over 7,000 third-party applications and that the platform syncs device coverage from Microsoft 365 and Active Directory rather than rediscovering assets, and audits MFA compliance via Microsoft 365. Compliance reporting is offered against Cyber Essentials, Essential 8, NIST, SOC 2, ISO 27001 and HIPAA.
Tanium
Vulnerability ManagementLarge enterprises needing real-time endpoint visibility and vulnerability assessment at massive scale with integrated remediation
Tanium is a converged endpoint management and security platform that includes vulnerability assessment as part of its broader endpoint visibility and control capabilities. Tanium's real-time endpoint architecture provides sub-15-second visibility across hundreds of thousands of endpoints, enabling security teams to discover vulnerabilities, assess configuration compliance, deploy patches, and verify remediation all within a single platform. Tanium's unique architecture makes it particularly powerful in large enterprises where real-time endpoint visibility at scale is critical.
Tenable
Vulnerability ManagementVulnerability management platform with Nessus scanning, cloud-native VM, and exposure management
Tenable is a widely adopted vulnerability management platform, offering a comprehensive suite of products including Tenable.io (cloud-based VM), Nessus (the world's most widely deployed vulnerability scanner), and Tenable.sc (on-premises management console). Tenable provides continuous visibility into every asset across the attack surface, identifying vulnerabilities, misconfigurations, and compliance violations across IT, cloud, containers, OT, and identity infrastructure. With over 200,000 organizations relying on Tenable, it has established itself as a widely adopted standard for enterprise vulnerability management.
Trivy
Application SecurityDevOps and platform engineering teams that need a fast, open-source vulnerability scanner for containers and Kubernetes environments with zero configuration overhead
Trivy is an open-source, comprehensive vulnerability scanner developed by Aqua Security that covers container images, file systems, Git repositories, Kubernetes clusters, and infrastructure-as-code configurations. Trivy stands out for its simplicity, speed, and breadth of scanning targets, requiring zero configuration to get started. It has become a widely adopted open-source scanner for container images in CI/CD pipelines and is widely adopted in Kubernetes-native environments for runtime vulnerability assessment.
Browse by Type
Related guides
Other categories you might be evaluating alongside vulnerability management.
About this listing
Vulnerability Management tools, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →