Curated list of affordable (free or low‑cost) vulnerability scanning and management tools that deliver solid coverage without breaking the budget.
Get targeted exposure with custom position pinning and highlighted placement.
Open‑source network vulnerability scanner with extensive CVE database, customizable scan policies, and PDF/HTML reporting.
Free network mapper that includes a rich library of NSE scripts for host discovery, service enumeration, and basic vulnerability checks.
Free, open‑source web application security scanner with automated spidering, active scanning, and easy integration into CI pipelines.
Lightweight, open‑source web server scanner that checks for outdated software, misconfigurations, and over 6,700 known vulnerabilities.
Simple, fast, open‑source scanner for container images, file systems, and Git repositories; detects OS packages, language libraries, and misconfigurations.
Open‑source static analysis tool for Docker and OCI images that continuously monitors for CVEs in layers and provides API access.
Free, open‑source container image scanning platform with policy‑as‑code, detailed vulnerability reports, and CI/CD integration.
Built‑in, free dependency‑alert service for public and private repos that automatically opens pull requests to fix vulnerable libraries.
Developer‑focused vulnerability platform offering free scans for open‑source dependencies, container images, and IaC templates (limited to 100 tests per month).
Open‑source multi‑cloud security auditing tool that enumerates misconfigurations across AWS, Azure, and GCP with clear risk scoring.
Free, open‑source cloud security scanner that checks AWS, Azure, and GCP accounts for insecure settings and known vulnerabilities.
Open‑source AWS security best‑practice assessment tool that runs CIS Benchmarks, checks for IAM misconfigurations, and reports findings in CSV/JSON.
Free, open‑source audit tool for Unix/Linux systems that performs extensive security checks, including vulnerability detection and hardening recommendations.
Open‑source compliance and vulnerability scanner that uses SCAP standards to evaluate Linux hosts against security baselines.
Agentless, open‑source vulnerability scanner for Linux/Unix that pulls CVE data from multiple sources and supports automated patching.
Free tier of Qualys VM offering up to 16 internal and external assets, basic scanning, and reporting—ideal for small environments.
Tenable’s cloud‑based scanner provides a low‑cost “Essentials” plan (up to 16 assets) with continuous monitoring and CVE mapping.
InsightVM offers a 30‑day free trial and a “Starter” license for up to 32 assets, delivering live dashboards and remediation tracking.
Limited‑feature free version that scans up to 10 pages for web vulnerabilities, providing detailed remediation guidance.
Free version of the popular web security testing suite; includes manual scanning, spidering, and basic vulnerability identification.
Open‑source web application vulnerability scanner that performs black‑box testing and generates detailed reports in HTML, XML, or JSON.
Feature‑rich, open‑source web vulnerability scanner with multi‑threaded crawling, extensive plugin library, and reporting formats.
Free Nessus license for students and small teams (up to 16 IPs) that provides comprehensive vulnerability detection and reporting.
Built‑in Azure security posture management that offers free basic vulnerability assessment for Azure VMs and containers.
Provides basic vulnerability scanning for GCP resources at no extra cost, with integration to Container Analysis for container images.
Amazon Inspector offers a limited number of free assessment runs per month for EC2 instances, detecting CVEs and network reachability issues.
Open‑source runtime security tool that includes vulnerability scanning of container images and runtime detection of anomalous behavior.
Open‑source cloud‑native runtime security engine that monitors system calls for suspicious activity, complementing vulnerability scanning.
Free, open‑source antivirus engine that can be used to scan files and containers for known malware signatures and embedded vulnerable binaries.
OWASP tool that scans project dependencies (Java, .NET, Node, Python) for known CVEs using NVD and other data sources.
Open‑source scanner focused on JavaScript libraries; identifies outdated client‑side components with known vulnerabilities.
Static analysis tool for Python that detects security issues and vulnerable third‑party packages.
Open‑source secret scanning tool that detects hard‑coded credentials, API keys, and tokens in source code repositories.
Free static analysis engine that supports custom security rules across many languages, helping find vulnerable code patterns.
Limited‑feature free version for small teams that provides static application security testing for common languages.