Skip to main content

Vulnerability Scanning

Vulnerability scanning tools inspect network hosts, container images, and cloud assets for unpatched software, misconfigurations, and known CVE exposures.

5 Tools Cataloged
ToolLicensePlatformsPricingAction
NiktoGPL-3.0-onlyLinux, macOS, WindowsOpen SourceProfile
NucleiMITLinux, macOS, WindowsFree / CommercialProfile
OPENVASGPL-2.0-only (C scanner); GPL-2.0-or-later (Rust)LinuxFree / CommercialProfile
VulsGPL-3.0-or-laterLinux, macOS, FreeBSD, WindowsFree / CommercialProfile
WPScanWPScan Public Source License (free for non-commercial use; commercial license required)Linux, macOSFree / CommercialProfile

Tools in Vulnerability Scanning

Nikto

Open Source

Web server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.

LicenseGPL-3.0-only
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later (Rust)
PlatformLinux

Vuls

Free / Commercial

Agentless vulnerability scanner for Linux hosts and container environments, reporting CVEs using multiple vulnerability feeds.

LicenseGPL-3.0-or-later
PlatformLinux, macOS, FreeBSD, Windows

WPScan

Free / Commercial

Identifies WordPress vulnerabilities through checks of users, themes, plugins, and files to support patch management and configuration review.

LicenseWPScan Public Source License (free for non-commercial use; commercial license required)
PlatformLinux, macOS

Frequently Asked Questions

What is Vulnerability Scanning?

Vulnerability scanning tools inspect network hosts, container images, and cloud assets for unpatched software, misconfigurations, and known CVE exposures.

What topics does the Vulnerability Scanning category cover?

Network Infrastructure Auditing, Continuous Threat Exposure Management (CTEM), Container Image Vulnerability Scanning, Authenticated Host Auditing, Asset Context & Risk Scoring

About Vulnerability Scanning

Vulnerability scanning tools check network hosts, cloud assets, and container images for unpatched software and configuration mistakes. The category covers network scanners like OpenVAS and Nuclei that probe hosts for known vulnerabilities by checking service versions, testing for default credentials, and sending detection payloads. Container and image scanners like Trivy inspect Docker images for vulnerable packages and misconfigurations before deployment. Exposure management platforms aggregate vulnerability findings with asset context, so teams can prioritize remediation based on which vulnerable systems are internet-facing or hold sensitive data. Authenticated scanners log into target systems to check installed software versions against vulnerability databases, producing more accurate results than unauthenticated network scans. The category has evolved toward continuous scanning and exposure management (CTEM), where scanners run continuously rather than in periodic batches, and findings are correlated with threat intelligence to prioritize patches for vulnerabilities being actively exploited. Free tools like OpenVAS and Nuclei provide broad coverage for teams without commercial budgets, while commercial platforms add asset correlation, risk scoring, and ticketing integration.

Covered Topics & Disciplines

Network Infrastructure AuditingContinuous Threat Exposure Management (CTEM)Container Image Vulnerability ScanningAuthenticated Host AuditingAsset Context & Risk Scoring