I was doing some scanning on a web application, I used OWASP zap and Nessus. The risks that these two detected were medium to low, very few vulnerabilities.
Then I tried nikto, and the results were huge. It detected potential risks with the database and other "Major security problems" I was just wondering because I know these scanners detect potential risks that you can try to exploit it's not 100% accurate but which one of the three is the best to rely on as a starting point when you perform a pen testing?