Alternatives to Vuls
Assess known vulnerabilities on Linux and FreeBSD systems. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Vuls
Assess known vulnerabilities on Linux and FreeBSD systems.
Replacements
Listings that take over the same core job as Vuls.
OpenVAS
Full-featured open-source vulnerability scanner.
OpenVAS is a full open-source network vulnerability scanner with scheduling and reporting, but it needs involved installation and feed synchronisation on a self-hosted Linux server.
Nessus
Widely used commercial vulnerability scanner.
Nessus is a closed-source commercial scanner with a large plugin library and compliance auditing, with the free Essentials edition capped at sixteen IP addresses.
Qualys Community Edition
Free, cloud-based edition of the Qualys security platform for asset discovery and vulnerability assessment.
Qualys Community Edition is a cloud-hosted freemium service combining vulnerability assessment and asset discovery, limited to a few IPs, with scan data stored at Qualys.
Trivy
Scan software and infrastructure for known security issues.
Trivy scans filesystems, containers and configuration for known issues from the command line on Windows, macOS and Linux, rather than assessing remote hosts.
Grype
Find known vulnerabilities in container images and filesystems.
Grype finds known vulnerabilities in container images and filesystems and can read SBOMs, focusing on packages rather than whole-system assessment of servers.
Similar software
Related functionality, not a direct replacement.
Lynis
Audit Unix-like systems for hardening opportunities.
OpenSCAP
Open source tools for scanning systems against SCAP security policies and hardening baselines.
Wazuh Agent
Endpoint agent that feeds a Wazuh server with security and compliance data.
DefectDojo
An open source, self-hosted vulnerability management platform that collects and tracks findings from security scanners.
Fleet
An open device management platform for MDM, software patching and vulnerability management across operating systems.
OSV-Scanner
Check project dependencies against the OSV vulnerability database.