Home / Threat Defense / Vulnerability Management

Vulnerability Management

Proactively identify and fix security weaknesses to prevent cyber threats and protect your assets.

Try these 172 AI Vulnerability Management Tools

bundler-audit
Free

bundler-audit View bundler-audit

A tool to run YARA rules against node_module folders to identify suspicious scripts

bWAPP
Free

bWAPP View bWAPP

Linux privilege escalation auditing tool for detecting security deficiencies in Linux kernels.

Buster
Free

Buster View Buster

A tool that finds unprotected secrets in container images or file systems, matching against a database of 140 secret types.

CakeFuzzer
Free

CakeFuzzer View CakeFuzzer

Command line interface for managing and inspecting images, policies, subscriptions, and registries with support for various operating systems and packages.

Censys
Free

Censys View Censys

OCaml bindings to the YARA scanning engine for integrating YARA scanning capabilities into OCaml projects

Clair
Free

Clair View Clair

A repository containing hourly-updated data dumps of bug bounty platform scopes

CloudJack
Free

CloudJack View CloudJack

Open source security auditing tool to search and dump system configuration.

Commix-Testbed
Free

Commix-Testbed View Commix-Testbed

A community effort to compile security advisories for Ruby libraries with a detailed directory structure.

CRT sh
Free

CRT sh View CRT sh

Open source web application security scanner with 200+ vulnerability identification capabilities.

CVE Scanning of Alpine base images using Multi Stage builds in Docker 17.05
Free

CVE Scanning of Alpine base images using Multi Stage builds in Docker 17.05 View CVE Scanning of Alpine base images using Multi Stage builds in Docker 17.05

A list of vulnerable applications for testing and learning

CVE Ape
Free

CVE Ape View CVE Ape

Compares target's patch levels against Microsoft vulnerability database and detects missing patches.

Cybersecurity Evaluation Tool (CSET)
Free

Cybersecurity Evaluation Tool (CSET) View Cybersecurity Evaluation Tool (CSET)

A tool to find and search for registered CVEs, creating a local CVE database for offline use.

Dagda
Free

Dagda View Dagda

testssl.sh is a free command line tool for checking server's TLS/SSL configurations with clear and machine-readable output.

Damn Vulnerable iOS App (DVIA)
Free

Damn Vulnerable iOS App (DVIA) View Damn Vulnerable iOS App (DVIA)

A fuzzer for detecting open redirect vulnerabilities

DefectDojo
Free

DefectDojo View DefectDojo

A tool for scanning websites with open .git repositories and dumping their content for Bug Hunting/Pentesting Purposes.

detect-secrets
Free

detect-secrets View detect-secrets

A free and open-source tool for identifying vulnerabilities in Joomla-based websites.

Dnscan
Free

Dnscan View Dnscan

Automated contextual security findings enrichment and impact evaluation tool for vulnerability management.

Docker Bench for Security
Free

Docker Bench for Security View Docker Bench for Security

Automate version scraping and vulnerability scanning for Ruby on Rails stacks.

dom-red
Free

dom-red View dom-red

Cloud-based service for testing and analyzing Android and iOS apps for malware, vulnerabilities, and security threats.

DorkSearch
Free

DorkSearch View DorkSearch

An open source project for static analysis of vulnerabilities in application containers

5.0