emerging · 0.8 capabilitymarket resourcedomain

Vulnerability Management

Score 23.8 / 100 122 providers +3 via APIs 24 APIs Search apis.io →
Business capabilities this tag reaches
Cybersecurity Management 2

Providers using this tag (122)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Exemplar 4 Complete, well-documented, and agent-ready
Strong 15 Solid coverage with minor gaps
Developing 34 Usable, with meaningful gaps to close
ProjectDiscoveryCompanyCybersecuritySecurityVulnerability Scanning1 API53.4PyntAPI TestingAPI SecuritySecurityApplication Security2 APIs52.7Qwiet AiCompanySecurityApplication SecuritySAST2 APIs52.7UpwindSecurityCloud SecurityCNAPP2 APIs52.0Snyk ContainerContainer ImagesContainersKubernetesSecurity1 API51.6AxoniusAsset ManagementCybersecuritySaaS ManagementSaaS Security1 API51.4HackNoticeCompanySecurityThreat IntelligenceCybersecurity1 API51.2SynackCompanySecurityPenetration Testing9 APIs50.5ScalarrCompanyCybersecurityRuntime SecurityAI Agent Security2 APIs50.2Method SecurityCompanySecurityCybersecurityOffensive Security1 API49.9AccuKnoxCompanySecurityCloud SecurityCloud Native Application Protection Platform4 APIs49.7Horizon3.aiCompanySecurityCybersecurityPenetration Testing1 API49.7FossaCompanySecuritySoftware Supply ChainOpen Source1 API49.6Google Cloud Security Command CenterCloud SecurityComplianceRisk ManagementSecurity1 API48.1Root (fka Slim.ai)CompanySecurityContainer Security1 API47.6PlerionCompanySecurityCloud SecurityCSPM1 API47.0SysdigCloud SecurityContainersKubernetesRuntime Security2 APIs46.8CyCognitoCompanyCybersecurityAttack Surface ManagementExposure Management1 API46.5RegScaleCompanyComplianceGovernance Risk and ComplianceContinuous Controls Monitoring3 APIs46.5DragosCompanyCybersecurityOT SecurityICS1 API46.2CoalitionCyber InsuranceInsuranceInsurtechRisk Management1 API45.9Red Hat Enterprise LinuxAutomationComplianceEnterpriseLinux2 APIs44.7BinarlyCompanySecurityFirmware SecuritySupply Chain Security1 API44.6CybleThreat IntelligenceCybersecurityAttack Surface ManagementInternet Scanning2 APIs43.6SocketCompanySecuritySoftware Supply Chain SecurityDependency Scanning1 API43.6Black DuckCompanyEnterpriseApplication SecuritySoftware Composition Analysis6 APIs43.2Forward NetworksCompanyNetworksNetwork AutomationNetwork Digital Twin1 API43.2StackHawkAPI SecurityApplication SecurityDASTSecurity Testing1 API42.6PlexTracCompanyCybersecurityPenetration Testing1 API42.2NucleiSecurity TestingTestingVulnerability ScanningDAST1 API41.8Rapid7SecuritySIEMXDR3 APIs41.0SAFE SecurityCompanySecurityCyber Risk QuantificationThird-Party Risk Management2 APIs41.0BalbixCompanyCybersecuritySecurityRisk Management1 API39.8Stream.SecurityCompanySecurityCloud SecurityCloud Detection and Response1 API39.5
Thin 20 Limited public surface area
Emerging 30 Early or largely undocumented
ArmisCompanyDefense GovernmentSecurityCybersecurity25.6ChainguardCloud-NativeContainer ImagesContainersDevSecOps6 APIs24.3TXOne NetworksCompanySecurityCybersecurityOperational Technology24.0ForescoutCompanyCybersecurityNetwork SecurityDevice Visibility3 APIs23.6Bishop FoxCompanyCybersecurityOffensive SecurityPenetration Testing1 API23.1Nebula SecurityCompanySecurityCybersecurity22.9Lacework FortiCNAPPCloud SecurityCNAPPComplianceThreat Detection1 API22.6KodemCompanyCybersecurityApplication SecurityRuntime Security1 API21.6BrinqaCompanyCybersecurityExposure Management1 API21.0Qi AnxinCompanySecurityCybersecurityThreat Intelligence2 APIs19.7Kenna SecurityCompanyCybersecurityRisk-Based Prioritization1 API19.0EchoCompanySecuritySupply Chain SecurityContainer Security18.8Zafran SecurityCompanySecurityCybersecurity18.1AsteliaCompanySecurityExposure Management17.5Orca SecurityAgentlessAPI SecurityCIEMCloud Security2 APIs16.8Copa (Project Copacetic)BuildKitCLICNCF SandboxContainer Patching3 APIs16.5RunsybilCompanySecurityOffensive SecurityPenetration Testing15.3depthfirstCompanySecurityApplication SecurityCybersecurity14.7WizCloud SecurityCNAPPCSPM1 API14.5CogentCompanySecurityCTEM14.1RavenCompanySecurityApplication SecurityRuntime Security14.0Novee SecurityCompanySecurityCybersecurityPenetration Testing12.6Efflux SystemsCompanySecurityCybersecurityAttack Surface Management1 API12.2RapidFortCompanySecurityContainer SecuritySoftware Supply Chain12.2EnclaveCompanySecurityApplication SecurityCloud Security11.9FlashpointCompanyThreat IntelligenceCybersecuritySecurity1 API11.7PenteraCompanyCybersecuritySecurityPenetration Testing11.7SparkleCompanySecurityApplication SecurityArtificial Intelligence11.6AverlonCompanySecurityArtificial Intelligence11.3Lupin & HolmesCompanyCybersecuritySecurityOffensive Security11.1
Minimal 18 Almost no public developer surface
Unrated 1 Not yet scored

APIs with this tag (24)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Exemplar 4 Complete, well-documented, and agent-ready
Strong 2 Solid coverage with minor gaps
Developing 6 Usable, with meaningful gaps to close
Thin 8 Limited public surface area
Emerging 3 Early or largely undocumented
Minimal 1 Almost no public developer surface

Companies reaching this through an API (3)

These companies publish an API, specification or operation carrying “Vulnerability Management” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.

NinjaOne Red Hat Synopsys

Score breakdown

Frequency
59.4
log-scaled weighted occurrences
Breadth
3.2
spread across providers
Quality lift
40.8
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Where this tag sits

122 providers carry this tag directly, and 148 counting the 4 narrower tags below — 26 more to reach.

Security broader Vulnerability Scanning 21 providers CVE 9 providers Exposure Management 23 providers Vulnerabilities 4 providers

Related tags

DevSecOps 35 co-occurrences Application Security 30 co-occurrences Vulnerabilities 21 co-occurrences Exposure Management 18 co-occurrences Cybersecurity 69 co-occurrences SBOM 15 co-occurrences Cloud Security 24 co-occurrences Attack Surface Management 15 co-occurrences

Where this tag comes from

Provider tag122
Api tag24
Openapi tag2
Openapi op tag8

Cohort brief

Auto-generated

The 119 providers in the APIs.io catalog tagged Vulnerability Management, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
119
all scored
Mean Kin Score
33.7
+10.8 vs catalog 22.9
Mean Agent Readiness
17.5
+5.6 vs catalog 11.9
Spread
3.4–80.6
median 34.7 · σ 19.2
How the 119 split by band
Exemplar 4Strong 15Developing 34Thin 20Emerging 30Minimal 16
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 36.9 23.2 +13.7 119
Operational Transparency 24.3 13.7 +10.6 119
Access Clarity 36.8 26.5 +10.3 119
Contract Quality 26.1 17.6 +8.5 119
Discoverability 65.3 58.1 +7.2 119
Contract Governance 9.9 6.3 +3.6 119

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 28% 14% +14
MCP server (first-party) 26% 12% +14
Agent Skills 0% 0% 0
OAuth scopes 18% 11% +7
Security 98% 98% 0
Arazzo workflows 3% 2% +1
Governance rules 14% 14% 0

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Snyk 80.6
  2. 2 ControlUp 75
  3. 3 Tenable 67.5
  4. 4 CrowdStrike 67.1
  5. 5 Sonatype 64.8
  6. 6 Mend 63.4
  7. 7 OpenText Cybersecurity 60.3
  8. 8 Feedly 59.6
  9. 9 Iru 59.5
  10. 10 Armor 59.4
Top by Agent Readiness
  1. 1 Feedly 66.9
  2. 2 Horizon3.ai 48.4
  3. 3 Snyk 43.7
  4. 4 Upwind 41.5
  5. 5 Armor 40.4
  6. 6 Tenable 39.2
  7. 7 CyCognito 38.7
  8. 8 Socket 36.9
  9. 9 OpenText Cybersecurity 36.7
  10. 10 watchTowr 36.5
All 122 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 5 October 2026, across 29093 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/vulnerability-management"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/vulnerability-management"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/vulnerability-management/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.