Vulners
Vulners operates an API-first vulnerability intelligence platform that aggregates 3M+ CVEs and exploits from 200+ sources, serving security operations, DevSecOps engineering, AI-agent builders, and OEM/white-label partners with tiered credit-metered subscriptions.
- Company typePrivate
- Founded2015
- HeadquartersWilmington, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Vulners does
Vulners is a private U.S.-incorporated vulnerability intelligence platform headquartered in Wilmington, Delaware, founded in 2015 and operating with 11-50 employees. It maintains a graph-linked corpus of 3M+ vulnerabilities and exploits aggregated from 200+ sources (NVD, vendor advisories, exploit databases, security feeds) and exposes them through a REST API on a 99.9% SLA backed by CDN delivery. The product portfolio consists of six core APIs — Vulnerability Intelligence (enriched CVE context with CVSS, EPSS, KEV, CWE, patches, exploits, and an internal AI Risk indicator), Assessment (deterministic inventory-to-CVE mapping without network probes, ~0.1s per component), Datasets (full corpus export for on-prem/data-lake ingestion with reproducibility timestamps), Alerts (webhook/email push notifications), Exploits (PoC and wild-exploitation tracking), and MCP (Model Context Protocol server delivering real-time vulnerability context to AI agents). Complementary solution packages include White-Label OEM embedding, Data Feeds, Security Automation SDK, Exploits & KEV prioritization, MCP for AI Agents, and add-on modules such as Perimeter Scanner, Library Audit (PURL-based supply-chain screening), and SBOM Analyzer (SPDX/CycloneDX ingestion).\n\nRevenue derives from a tiered, credit-metered API subscription: a perpetual free tier (100 credits/month) feeding a self-serve funnel, Basic at $600/month (600 credits), Pro at $1,300/month (3,000 credits), and a Custom OEM tier priced individually with multi-year contract flexibility for white-label partners. Payment supports monthly, quarterly, or annual billing in USD or EUR via wire, card, or PayPal. Go-to-market is dual-motion: an API-first PLG motion for developers and product teams (with a 30-day trial), plus an OEM/embedded motion that lets partners ship Vulners intelligence under their own brand without building their own vulnerability database — Vulners supplies API/SDK access, engineering support, and flexible licensing. Target buyers cut horizontally across security operations teams, DevSecOps engineering groups building pre-release gates and CI/CD checks, AI/ML platform builders needing live CVE context for agents, and OEM technology vendors seeking fast time-to-market. Distribution is global with no geographic restrictions declared; all revenue materials, customer engagement, and demo bookings route through founder Andrey Lukashenkov.
Vulners firmographics
Firmographics- Name
- Vulners
- Legal name
- Vulners inc.
- Website
- https://vulners.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Vulners operates an API-first vulnerability intelligence platform that aggregates 3M+ CVEs and exploits from 200+ sources, serving security operations, DevSecOps engineering, AI-agent builders, and OEM/white-label partners with tiered credit-metered subscriptions.
- Ownership category
- akta.pro rank
Vulners industry classification
Industry- Product category
- Vulnerability Intelligence Software
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where Vulners is headquartered
LocationHeadquarters
- HQ city
- Wilmington
- HQ country
- United States
- HQ region
- North America
Markets served
Vulners business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Marketing or Sales, Operations
Revenue model
- API Subscription (Tiered): Subscription-based pricing with tiered API credit allocation. Free tier (100 credits/month), Basic ($600/month, 600 credits), Pro ($1,300/month, 3000 credits), and Custom OEM pricing. Credits consumed based on API call complexity ranging from 1-100 credits per operation.
- Usage-Based API Credits: Credit-based billing where complexity of each API call determines credit consumption. Search operations cost 2 credits, audit operations 2-3 credits, IoC data 1 credit, dataset exports 100 credits, perimeter scans 1-2 credits.
- OEM/White-Label Licensing: Custom OEM licensing model for partners embedding vulnerability intelligence in their products. Flexible partner/OEM pricing with engineering support included.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free - 100 API credits/month for perpetual free access |
| Subscription | Monthly | Basic - $600/month with 600 API credits |
| Subscription | Monthly | Pro - $1,300/month with 3000 API credits |
| Subscription | Multi-year contract | OEM - Custom pricing by request |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels5 records
Vulners product offering
Product offeringCore offering
Vulners provides an API-driven vulnerability intelligence platform that aggregates more than 3M vulnerabilities, exploits, advisories, and KEV entries from sources such as NVD, OSV, GHSA, Exploit-DB, Metasploit, and CISA into a single normalized data layer. Customers consume this intelligence through six core products (Vulnerability Intelligence, Assessment, Datasets, Alerts, Exploits, MCP) and packaged solutions such as White Label, Data Feeds, Security Automation SDK, Exploits & KEV, and MCP for AI Agents. The platform is sold to security operations teams, product/devsecops engineers, AI builders, and OEM partners via freemium, credit-based, and enterprise licensing.
Product overview
Vulners is a vulnerability intelligence platform offering a unified database of 3M+ vulnerabilities and exploits with multiple product tiers. The core portfolio consists of six integrated products: Vulnerability Intelligence (enriched CVE data via API), Assessment (inventory-to-report conversion), Datasets (bulk export for research), Alerts (real-time notifications), Exploits (PoC and wild exploitation tracking), and MCP (AI agent integration). These products share a graph-linked corpus and REST API with 99.9% SLA, and are complemented by solution packages (White Label OEM licensing, Data Feeds, Security Automation SDK, Exploits & KEV prioritization) and add-on features (Perimeter Scanner, Library Audit, SBOM Analyzer). Pricing spans Free (100 API credits/month), Basic ($600/month for 600 credits), Pro ($1,300/month for 3,000 credits), and custom OEM plans.
Differentiator
Problem solved
Functional benefit
Brands
- White Label: Build Faster, Earn More, and Innovate Freely - Vulners White-Label Solutions let you ship vulnerability intelligence inside your own product without building and maintaining a vulnerability database or detection logic.
Products and services
- Vulnerability Intelligence
Companies that use Vulners
Customer profileSegments5 records
Ideal customer profiles4 records
Vulners technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability3 records
Feature6 records
Vulners partnerships and signals
Strategic signalScale indicators3 records
Recent moves6 records
Expansion highlights5 records
Vulners competitors and assessment
Company assessmentBroad incumbents
- Qualys: Qualys offers a cloud-based vulnerability and security posture platform, including its own curated vulnerability data and APIs (Qualys Threat DB) that overlap with Vulners' intelligence and assessment use cases for enterprise customers.
- Recorded Future: Recorded Future provides broad threat intelligence including vulnerability and exploit intelligence via API, overlapping with Vulners' intelligence, alerts, and prioritization use cases for enterprise SOCs.
- Rapid7: Rapid7's Metasploit and InsightVM platforms include curated vulnerability research, exploit metadata, and intelligence APIs (e.g., AttackerKB) that compete with Vulners' exploit and KEV tracking offerings.
- Tenable: Tenable operates Nessus and a broad vulnerability management platform, with internal vulnerability data feeds and intelligence (Tenable Research) that compete with Vulners at the data layer, particularly for enterprise SOC and VM buyers.
- Cisco Vulnerability Management (Kenna Security): Kenna Security, now part of Cisco, delivers risk-based vulnerability intelligence with exploit prediction and prioritization signals — a comparable intelligence-plus-prioritization proposition to Vulners' CVE Fusion and Exploits products.
Emerging players
- Snyk: Snyk focuses on developer-first security including vulnerability data for open source dependencies and SBOM-based workflows, competing with Vulners' Library Audit, SBOM Analyzer, and supply-chain intelligence use cases.
- Chainguard: Chainguard provides secure container images and software supply-chain intelligence, including vulnerability and CVE data on container packages — overlapping with Vulners' SBOM and library audit capabilities for DevSecOps buyers.
- Nucleus Security: Nucleus Security is a vulnerability management platform that aggregates vulnerability data feeds and prioritizes risk, with API integrations similar to Vulners' positioning as an enrichment backend for SIEM and VM platforms.
Direct peers
- VulnDB (Risk Based Security / Flashpoint): VulnDB is a commercial vulnerability database and intelligence service with normalized vendor advisories, exploited-vulnerability tracking, and API access — directly comparable to Vulners' data corpus and API-first product.
- VulnCheck: VulnCheck offers a commercial vulnerability intelligence platform with prioritized CVE data, exploit and KEV tracking, and an API for security teams — a near-direct competitor to Vulners' core Vulnerability Intelligence and Exploits products.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Vulners social profiles
Digital presenceVulners financial estimates
Financial estimateRevenue estimate
Valuation estimate
Vulners leadership team
Management profileNumber of profiles
Profiles1 record
Vulners funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Vulners M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Vulners
What does Vulners do?
Vulners provides an API-driven vulnerability intelligence platform that aggregates more than 3M vulnerabilities, exploits, advisories, and KEV entries from sources such as NVD, OSV, GHSA, Exploit-DB, Metasploit, and CISA into a single normalized data layer. Customers consume this intelligence through six core products (Vulnerability Intelligence, Assessment, Datasets, Alerts, Exploits, MCP) and packaged solutions such as White Label, Data Feeds, Security Automation SDK, Exploits & KEV, and MCP for AI Agents. The platform is sold to security operations teams, product/devsecops engineers, AI builders, and OEM partners via freemium, credit-based, and enterprise licensing.
Is Vulners a public or private company?
Vulners is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Vulners founded?
Vulners was founded in 2015. It employs 11 to 50 people.
Where is Vulners based?
Vulners is headquartered in Wilmington, United States, in the North America region.
How does Vulners make money?
Three revenue lines are on record. API Subscription (Tiered) is the primary driver. The others are usage-Based API Credits and OEM/White-Label Licensing.
Who are Vulners's main competitors?
Broad incumbents on record are Qualys, Recorded Future, Rapid7, Tenable and Cisco Vulnerability Management (Kenna Security). Emerging players are Snyk, Chainguard and Nucleus Security. Direct peers are VulnDB (Risk Based Security / Flashpoint) and VulnCheck.
Does Vulners have an API?
Yes. The Vulners REST API offers reliable, high-performance access to vulnerability intelligence, with 99.9% SLA uptime and CDN-backed data delivery for seamless global access. API billing is based on API credits with different credit costs per endpoint type. Supports database search, vulnerability assessment for Linux/Windows hosts, CVE lookups, CPE queries, IoC data retrieval, dataset exports, and perimeter scanning. Developer documentation is at docs.vulners.com/docs/api.
What industry is Vulners in?
Vulners's product category is Vulnerability Intelligence Software. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7372.