Vulny

Vulnerability scanning

Vulny continuously checks your internet-facing servers and web applications for known vulnerabilities, misconfigurations and exposed services — safely, without harming your site.

What does a vulnerability scan actually check?

A vulnerability scan checks which of your internet-facing services an attacker could break into. Vulny first discovers every open port and fingerprints the exact software and version running behind it — web servers, databases, mail and remote-access services. It then matches each one against a detection database of 357,755+ vulnerability tests covering known CVEs, misconfigurations, exposed files and weak SSL/TLS. Every match is enriched with its CVSS severity, whether it appears on the CISA KEV list of vulnerabilities known to be exploited in the wild, its EPSS exploit probability, and whether public exploit code exists. The result is a clear inventory of what is exposed on your perimeter and which weaknesses are genuinely reachable — the same view an attacker builds during reconnaissance, delivered safely and without touching or harming your systems.

How does Vulny decide which vulnerabilities to fix first?

Vulny ranks every finding by real-world risk, so your team fixes the handful that matter instead of drowning in a list of thousands. Not all CVEs are equal: most are never exploited, while a small fraction are weaponised within days of disclosure. Vulny weighs three signals to tell them apart — the CVSS severity score, whether working exploit code is publicly available, and the EPSS probability that the flaw will actually be exploited. It also flags anything on the CISA KEV catalogue, which lists vulnerabilities confirmed to be exploited in the wild. A medium-severity bug being attacked right now is prioritised above a high-severity one with no known exploit. The outcome is a short, ordered worklist where the top items are the ones an attacker would reach for first.

How often does Vulny check for new vulnerabilities?

Vulny re-checks your assets against newly published vulnerabilities every two hours, not just during a scheduled scan. New CVEs are imported from the National Vulnerability Database (NVD) around the clock, and the moment one is published Vulny compares it against the software and versions it already knows you run. If a brand-new vulnerability affects something on your perimeter, it opens an issue and alerts you the same day it is disclosed — typically long before the next routine scan would have caught it. This matters because attackers often weaponise fresh vulnerabilities within hours of publication, so a clean report from last week is no guarantee today. Continuous re-checking closes that gap; see Emerging Threat Scans for how Vulny surfaces today’s live threats against your specific assets.

See it on your own site

Run one scan for security, SEO and AI-search (GEO) — and get a branded, ISO 27001 ready PDF report.

Scan my site →