Vulnerability Management Tools
Compare the best vulnerability management tools. Discover, prioritize, and remediate vulnerabilities across your attack surface.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
JupiterOne is fundamentally a data platform for managing all of your assets and security integrations. They can create custom dashboards, queries, and graphs across assets and vulnerability data.
Acquired by Wiz. Dazz aggregates your security vulnerabilities into a single dashboard which allows easy assignment and risk based prioritization. Their approach to this problem does a lot of automated lookup work and has some advanced ability to find where container images are coming from. Dazz differentiates by being focused on remediation, rather than just prioritization.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Intruder offers holistic network vulnerability scanner, DAST, and CSPM scanning solutions, a great option for mid size businesses looking for a flexible scanner
Tamnoon is one of the first cloud focused MDR/MSSPs that helps you prioritize, fix, and respond to CNAPP, CSPM, and CDR alerts. The use a combination of humans and AI guidance to help fix your detection backlog.
Phoenix security is more on the vulnerability management side of ASPM, but they offer their own SCA and DAST options alongside existing scanners. Due to the emphasis on management & orchestration, they offer a wide variety of contextualizations and in depth vulnerability data. An especially great fit for enterprises.
Due to their beginnings focusing on runtime environments, DevOcean has created an amazing combination of features - from code to cloud visibility, combined with insights from log data, and a lot of data enrichment to assets, not just vulnerabilities.
Acquired by Tenable. Vulcan offers the robust flexibility of the legacy offerings in this category, but with a much nicer UI/UX. A strong choice for enterprises looking to manage huge amounts of very diverse assets, but a lot of the setup will be manual tinkering (no worse than the incumbents).
Maze uses agentic AI to find the exploitability of vulnerabilities in cloud environments, increasing the risk score for true positives, while giving demonstrable proof when false positives cannot be exploited.
Acquired by Orca Security, Opus focuses on providing root cause analysis - mostly with containers and IaC. Their foundation is building resources and ownership, and then enabling alerting and communication per group to be flexible to different workflows. They provide workflows upon vulnerability detection.
Acquired by ZScaler. Avalor creates a platform for the vulnerability fixes you're probably coding yourself. They offer an elegant no/low code approach for uniting all of your vulnerability data in one place. Their approach heavily relies on the flexibility of their data standardization.
Zafran has built a vulnerability management platform focused on risk prioritization and response/mitigation actions that can be taken while things are getting fixed. Their main differentiator is taking into account mitigating security controls that are in place.
Tromzo pulls in rich metadata from your various tools, and uses that metadata to create groupings and prioritizations of your vulnerabilities. They uniquely offer a yaml file for adding custom tools and pulling together data.
Tonic accelerates prioritization and remediation of vulnerabilities and threats, with a Context-Driven Unified Exposure Management platform. Powered by Agentic AI and a security Data Fabric, Tonic extracts meaningful and actionable context from unstructured organizational knowledge and threat intelligence, empowering security teams with superior visibility, dramatic reduction in false positives, and a sharp focus on findings that matter. Leading organizations, including Fortune 500 companies, rely on Tonic to slash remediation time and reduce risk to key business processes.
Acquired by Armis. Silk Security offers some unique features like assigning ownership to domains, and provides the rare value of showing asset ownership and code to cloud asset tracking. Another unique feature is their leaderboard - something not enough products have leaned into as a motivator.