How APVISO compares
52 vulnerability types tested across 6 security tools. See which detections each tool catches and which it misses.
Detection Coverage
52 vulnerability types, 5 tools
Side-by-side detection comparison across leading security tools
| Vulnerability | APVISO | Burp Suite | Acunetix | Nessus | w4af | Wapiti |
|---|---|---|---|---|---|---|
Search query injectioncritical | ||||||
Database schemacritical | ||||||
SQLi logincritical | ||||||
User credentialscritical | ||||||
API-only XSShigh | ||||||
Admin registrationhigh | ||||||
Arbitrary file writehigh | ||||||
Change password (CSRF)high | ||||||
User settings (CSRF)high | ||||||
Cross-domain datahigh | ||||||
Forged signed JWThigh | ||||||
Local file readhigh | ||||||
NoSQL DoShigh | ||||||
NoSQL exfiltrationhigh | ||||||
NoSQL manipulationhigh | ||||||
Template injectionhigh | ||||||
Server-side XSShigh | ||||||
Successful RCE DoShigh | ||||||
XXE data accesshigh | ||||||
XXE DoS attackhigh | ||||||
Access logmedium | ||||||
Blocked RCE DoSmedium | ||||||
CAPTCHA bypassmedium | ||||||
CSP bypassmedium | ||||||
Client-side XSSmedium | ||||||
DOM-based XSSmedium | ||||||
Object modificationmedium | ||||||
Validation bypassmedium | ||||||
HTTP header XSSmedium | ||||||
Payload manipulationmedium | ||||||
Payback manipulationmedium | ||||||
Reflected XSSmedium | ||||||
SSRF attackmedium | ||||||
Vulnerable librarymedium | ||||||
Allowlist bypasslow | ||||||
Password strengthlow | ||||||
Confidential documentlow | ||||||
Error handlinglow | ||||||
Exposed metricslow | ||||||
Developer backuplow | ||||||
Repetitive registrationlow | ||||||
Upload sizelow | ||||||
Upload typelow | ||||||
Video XSS payloadlow | ||||||
Session manipulationlow | ||||||
CSP misconfigurationlow | ||||||
Robots.txtlow | ||||||
HTTP methodsinfo | ||||||
Password lengthinfo | ||||||
HttpOnly cookieinfo | ||||||
Secure cookieinfo | ||||||
SameSite cookieinfo | ||||||
| Total Detected | 45/52 | 8/52 | 11/52 | 3/52 | 3/52 | 2/52 |
Run your first autonomous pentest
Use APVISO for real-time findings, developer-ready evidence, and retests built into the workflow.
Contact sales