Alternatives to Vuls

Assess known vulnerabilities on Linux and FreeBSD systems. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Vuls.

  • OpenVAS

    Full-featured open-source vulnerability scanner.

    OpenVAS is a full open-source network vulnerability scanner with scheduling and reporting, but it needs involved installation and feed synchronisation on a self-hosted Linux server.

  • Nessus

    Widely used commercial vulnerability scanner.

    Nessus is a closed-source commercial scanner with a large plugin library and compliance auditing, with the free Essentials edition capped at sixteen IP addresses.

  • Qualys Community Edition

    Free, cloud-based edition of the Qualys security platform for asset discovery and vulnerability assessment.

    FreemiumProprietaryWeb

    Qualys Community Edition is a cloud-hosted freemium service combining vulnerability assessment and asset discovery, limited to a few IPs, with scan data stored at Qualys.

  • Trivy

    Scan software and infrastructure for known security issues.

    Trivy scans filesystems, containers and configuration for known issues from the command line on Windows, macOS and Linux, rather than assessing remote hosts.

  • Grype

    Find known vulnerabilities in container images and filesystems.

    Grype finds known vulnerabilities in container images and filesystems and can read SBOMs, focusing on packages rather than whole-system assessment of servers.

Similar software

Related functionality, not a direct replacement.