A tool that automatically opens pull requests with deterministic, proof-verified security patches instead of just flagging issues.
#vulnerability-scanning
52 tools curated in this category — including Railo, VulnScout, IntelOwl
techFind on mySelectas all sites and tools related to vulnerability-scanning. This selection of 52 resources is reviewed and maintained by the community. The most popular include Railo, VulnScout, IntelOwl. Each tool comes with a review, tags, comparisons and alternatives to help you make the best choice.
Takes the list of every open-source component your software depends on (its SBOM) and tells you which ones have known security holes, then gives you a web dashboard to triage and report on them — rather than making you cross-reference vulnerability databa
When a suspicious IP address, file, or link crosses an analyst's desk, checking it properly means querying a dozen different services (VirusTotal, Shodan, MISP...) one by one. IntelOwl does all those lookups at once through a single dashboard, for free.
A security team running five different scanners (one for containers, one for code, one for dependencies...) ends up with five different spreadsheets of findings, half of them duplicates. DefectDojo pulls all of that into one place, removes the duplicates,
A free, open-source vulnerability scanner that combines fast, deterministic security checks with an optional AI agent that plans and triages findings on its own — built for penetration testers and security teams who want automation without losing precisio
A free, open-source OWASP project that scans your project's lockfile for known vulnerabilities and hands you copy-and-run fix commands — dependency security that lives in your terminal instead of buried in a CI dashboard you check once a week.
Scans AI-generated codebases for exposed keys, vulnerable dependencies, and authorization flaws, with plain-English fixes.
A website security checkup you can run without installing anything or touching your server — point it at your site's address and it comes back with a report card grading how exposed you are, from A+ to F.
A free scanner that catches a mistake almost every web team makes eventually: accidentally leaving a real API key or database password visible in a website's code where anyone can copy it.
An open-source, self-hosted platform where security teams drag and drop building blocks to automate scans, alerts, and investigations — instead of stitching together scripts by hand.
A free command-line scanner that checks MCP servers — the plugins AI agents connect to — for hidden dangers like prompt injection or path traversal before you let an AI agent talk to them.
A free command-line tool that finds and organizes publicly-published exploit code for known security vulnerabilities (CVEs), so researchers don't have to manually search GitHub one CVE at a time.
A free tool that answers a question security teams often can't: "if an attacker ran this exact command on our systems, would our monitoring actually notice?" It checks scripts against known attack techniques and scores how visible they'd be to your defens
A compliance platform that pairs automated evidence-gathering software with actual licensed auditors on staff, so the same company that helps you prepare for SOC 2 or ISO 27001 can also perform the audit itself.
Automates the grinding paperwork behind security certifications like SOC 2 or ISO 27001 — connecting to your cloud tools, continuously collecting the evidence an auditor needs, and flagging anything that would fail before the real audit happens.
Free open-source tool that scans a Tailscale network for security misconfigurations — overly open access rules, weak auth settings, risky device permissions — and tells you exactly what to fix.
A security platform that scans your code, pipelines, and AI coding tools for vulnerabilities across your whole software supply chain, then tries to auto-fix what it finds.
Free secrets scanner from Gitleaks' original creator: finds leaked API keys and passwords in code with far fewer false positives.
AI-powered security platform combining automated pentesting, code review and cloud vulnerability scanning to find and fix exploitable issues before attackers do.
Open-source LLM eval and red teaming: test prompts, compare models, catch jailbreaks and data leaks locally and in CI.