emerging · 0.1

Vulnerability Management

Score 22.9 / 100 115 providers +3 via APIs 26 APIs Search apis.io →

Providers using this tag (115)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Exemplar 1 Complete, well-documented, and agent-ready
Strong 8 Solid coverage with minor gaps
Developing 37 Usable, with meaningful gaps to close
OpenText CybersecurityCybersecurityApplication SecuritySAST1 API54.2TenableCompanyEnterpriseCybersecurity8 APIs53.6Cisco PSIRT openVuln APISecurityThreat IntelligenceDisclosure1 API53.3Qwiet AiCompanySecurityApplication SecuritySAST2 APIs53.0UpwindSecurityCloud SecurityCNAPP2 APIs53.0FleetCompanyDeveloper ToolsDevice ManagementMDM1 API52.8PyntAPI TestingAPI SecuritySecurityApplication Security2 APIs52.5Amazon IoT Device DefenderComplianceIoTSecurity1 API52.2ProjectDiscoveryCompanyCybersecuritySecurityVulnerability Scanning1 API52.1Snyk ContainerContainer ImagesContainersKubernetesSecurity1 API51.8HackNoticeCompanySecurityThreat IntelligenceCybersecurity1 API51.3ArmorCompanyCybersecurityManaged Detection and ResponseCloud Security16 APIs51.1RegScaleCompanyComplianceGovernance Risk and ComplianceContinuous Controls Monitoring3 APIs50.9CoalitionCyber InsuranceInsuranceInsurtechRisk Management1 API50.2ScalarrCompanyCybersecurityRuntime SecurityAI Agent Security2 APIs49.2SysdigCloud SecurityContainersKubernetesRuntime Security2 APIs49.0FossaCompanySecuritySoftware Supply ChainOpen-Source1 API48.5VulnCheckCompanySecurityVulnerability IntelligenceExploit Intelligence1 API48.4SynackCompanySecurityPenetration Testing9 APIs48.0AccuKnoxCompanySecurityCloud SecurityCloud Native Application Protection Platform4 APIs47.0Root (fka Slim.ai)CompanySecurityContainer Security1 API46.6PlerionCompanySecurityCloud SecurityCSPM1 API46.3Google Cloud Security Command CenterCloud SecurityComplianceRisk ManagementSecurity1 API46.1MendApplication SecuritySoftware Composition AnalysisSASTContainer Security2 APIs46.1Horizon3.aiCompanySecurityCybersecurityPenetration Testing1 API46.0CyCognitoCompanyCybersecurityAttack Surface ManagementExposure Management1 API45.7DragosCompanyCybersecurityOT SecurityICS1 API45.6BinarlyCompanySecurityFirmware SecuritySupply Chain Security1 API44.7CybleThreat IntelligenceCybersecurityAttack Surface ManagementInternet Scanning2 APIs42.8SocketCompanySecuritySoftware Supply Chain SecurityDependency Scanning1 API42.5StackHawkAPI SecurityApplication SecurityDASTSecurity Testing1 API42.4Forward NetworksCompanyNetworksNetwork AutomationNetwork Digital Twin1 API41.8Rapid7SecuritySIEMXDR3 APIs41.8Red Hat Enterprise LinuxAutomationComplianceEnterpriseLinux2 APIs41.7Cybersecurity and Infrastructure Security AgencyAdvisoriesAISBinding Operational DirectiveCSAF1 API40.8PlexTrac, LLCCompanyCybersecurityPenetration Testing1 API40.2Stream.SecurityCompanySecurityCloud SecurityCloud Detection and Response2 APIs39.3
Thin 22 Limited public surface area
Emerging 31 Early or largely undocumented
CynomiCompanyCybersecuritySecurityCompliance1 API26.0DeepwatchCompanyCybersecurityManaged Detection and ResponseSecurity Operations1 API26.0TolmoCompanySecurityCybersecurityCloud Security1 API25.7ChainguardCloud-NativeContainer ImagesContainersDevSecOps6 APIs25.2Jit (fka Cbrix)CompanyCybersecurityApplication SecurityDevSecOps1 API25.2Nebula SecurityCompanySecurityCybersecurity22.7ForescoutCompanyCybersecurityNetwork SecurityDevice Visibility3 APIs22.5TXOne NetworksCompanySecurityCybersecurityOperational Technology22.1QualysSecurityComplianceVMDR2 APIs21.9BrinqaCompanyCybersecurityExposure Management1 API21.2KodemCompanyCybersecurityApplication SecurityRuntime Security1 API20.4Bishop FoxCompanyCybersecurityOffensive SecurityPenetration Testing1 API20.3Kenna SecurityCompanyCybersecurityRisk-Based Prioritization1 API19.9Copa (Project Copacetic)BuildKitCLICNCF SandboxContainer Patching3 APIs19.2Qi AnxinCompanySecurityCybersecurityThreat Intelligence2 APIs18.7EchoCompanySecuritySupply Chain SecurityContainer Security17.6AsteliaCompanySecurityExposure Management17.4Zafran SecurityCompanySecurityCybersecurity17.2RunsybilCompanySecurityOffensive SecurityPenetration Testing15.1depthfirstCompanySecurityApplication SecurityCybersecurity14.6WizCloud SecurityCNAPPCSPM1 API14.6RavenCompanySecurityApplication SecurityRuntime Security14.4CogentCompanySecurityCTEM13.8Efflux SystemsCompanySecurityCybersecurityAttack Surface Management1 API13.3FlashpointCompanyThreat IntelligenceCybersecuritySecurity1 API13.3Novee SecurityCompanySecurityCybersecurityPenetration Testing13.3RapidFortCompanySecurityContainer SecuritySoftware Supply Chain12.7PenteraCompanyCybersecuritySecurityPenetration Testing12.2TAAI Labs, IncCompanySecurityApplication SecurityArtificial Intelligence11.8EnclaveCompanySecurityApplication SecurityCloud Security11.3RemedioCompanyCybersecuritySecurityRemediation11.2
Minimal 14 Almost no public developer surface
Unrated 2 Not yet scored

APIs with this tag (25)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 6 Solid coverage with minor gaps
Developing 5 Usable, with meaningful gaps to close
Thin 10 Limited public surface area
Emerging 4 Early or largely undocumented

Companies reaching this through an API (3)

These companies publish an API, specification or operation carrying “Vulnerability Management” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.

NinjaOne Red Hat Synopsys

Score breakdown

Frequency
59.1
log-scaled weighted occurrences
Breadth
3.2
spread across providers
Quality lift
36.8
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

DevSecOps 36 co-occurrences Application Security 31 co-occurrences Exposure Management 18 co-occurrences Cybersecurity 65 co-occurrences SBOM 15 co-occurrences Attack Surface Management 15 co-occurrences Vulnerabilities 15 co-occurrences Cloud Security 23 co-occurrences

Where this tag comes from

Provider tag115
Api tag26
Openapi tag3
Openapi op tag8

Cohort brief

Auto-generated

The 112 providers in the APIs.io catalog tagged Vulnerability Management, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
112
all scored
Mean Kin Score
32.7
+8.8 vs catalog 23.9
Mean Agent Readiness
17.5
+5.5 vs catalog 12
Spread
5–71.3
median 34.2 · σ 17
How the 112 split by band
Exemplar 1Strong 8Developing 37Thin 22Emerging 31Minimal 13
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 37.2 23.4 +13.8 112
Operational Transparency 24.4 14 +10.4 112
Contract Quality 28 19.8 +8.2 112
Access Clarity 34.7 26.5 +8.2 112
Discoverability 66.8 61.2 +5.6 112
Contract Governance 9.4 6.4 +3 112

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 23% 10% +13
MCP server (first-party) 25% 13% +12
Agent Skills 0% 0% 0
OAuth scopes 18% 11% +7
Security 98% 97% +1
Arazzo workflows 4% 2% +2
Governance rules 10% 14% -4

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Snyk 71.3
  2. 2 ControlUp 65.6
  3. 3 Feedly 59.4
  4. 4 GreyNoise Intelligence 59.3
  5. 5 Kondukto 57.8
  6. 6 Iru 57.5
  7. 7 Xbow 55.9
  8. 8 Method Security 55.1
  9. 9 Malwarebytes 54.6
  10. 10 OpenText Cybersecurity 54.2
Top by Agent Readiness
  1. 1 Feedly 63.3
  2. 2 Horizon3.ai 48.4
  3. 3 Snyk 43.7
  4. 4 Upwind 43.7
  5. 5 Nucleus Security 41.7
  6. 6 Armor 40.4
  7. 7 CyCognito 38.7
  8. 8 Tenable 36.7
  9. 9 watchTowr 36.5
  10. 10 ControlUp 35.7
All 115 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 15 September 2026, across 27661 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/vulnerability-management"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/vulnerability-management"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/vulnerability-management/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.