Home / Threat Defense / Vulnerability Management

Vulnerability Management

Proactively identify and fix security weaknesses to prevent cyber threats and protect your assets.

Try these 172 AI Vulnerability Management Tools

npm-zoo
Free

npm-zoo

A free and open-source deliberately insecure web application for security enthusiasts, developers, and students to discover and prevent web vulnerabilities.

Nucleus Security Platform
Free

Nucleus Security Platform

A free and open-source deliberately insecure web application for security enthusiasts, developers, and students to discover and prevent web vulnerabilities.

ocaml-yara by Elastic
Free

ocaml-yara by Elastic

A demonstration site for the Acunetix Web Vulnerability Scanner, intentionally vulnerable to various web-based attacks.

Opus
Free

Opus

An open-source tool for finding security vulnerabilities, compliance issues, and infrastructure misconfigurations in infrastructure-as-code

OverTheWire: Vortex
Free

OverTheWire: Vortex

LeakIX is a red-team search engine that indexes mis-configurations and vulnerabilities online.

OWASP API Security Top 10
Free

OWASP API Security Top 10

A non-profit organization focused on improving the security of software through resources and training.

OWASP Application Security Wiki
Free

OWASP Application Security Wiki

Linux Exploit Suggester; suggests possible exploits based on the Linux operating system release number.

OWASP Bricks
Free

OWASP Bricks

Pac-resolver, a popular NPM package with 3 million weekly downloads, has a severe remote code execution flaw.

OWASP Foundation
Free

OWASP Foundation

Advanced vulnerability assessment tool for gaining visibility and preventing cyber attacks.

OWASP Joomla Vulnerability Scanner
Free

OWASP Joomla Vulnerability Scanner

An OSINT tool that generates username lists for companies on LinkedIn for social engineering attacks or security testing purposes.

OWASP TOP 10 Presentation
Free

OWASP TOP 10 Presentation

Vulnerability scanner for Linux/FreeBSD, written in Go, agent-less, informs users of vulnerabilities related to the system and affected servers.

pac-resolver
Free

pac-resolver

FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.

Packet Storm Exploits for April 2024
Free

Packet Storm Exploits for April 2024

tfsec is being replaced by Trivy, a more comprehensive open-source security solution

Pagodo
Free

Pagodo

A hosted web application security testing tool that enables security researchers to register, activate their accounts, and scan web applications for vulnerabilities.

ParamPamPam
Free

ParamPamPam

tfsec is being replaced by Trivy, a more comprehensive open-source security solution

Phoenix
Free

Phoenix

Automate your reconnaissance process with AttackSurfaceMapper, a tool for mapping and analyzing network attack surfaces.