Try Security Findings Deduplicator — free

Compare two security-scanner finding exports as CSV (e.g. from two different scanners, or a current scan vs a known/triaged baseline). Each row is a finding with fields like tool, severity, title/cve, asset/host, and a fingerprint key (use cve+asset, or title+asset, or the first column if none). Detect and report: DUPLICATE findings that appear in BOTH files (same finding key) so teams stop triaging the same issue twice; findings UNIQUE to file A; findings UNIQUE to file B; and within each file, repeated/duplicate rows. Output a summary with counts per category plus the deduplicated/overlapping findings list, ordered by severity (critical>high>medium>low) when severity is present. Free to try, no signup — a subscription unlocks the full report and export.