I got a large number of reports for a Debian system running Apache. These were all old vulnerabilities where fixes were backported to Debian's packages, so these are false positives. Also got a warning for another server about the recent XMSS issue in OpenSSH, which is code that is disabled by default (and disabled on the scanned server).
It seems all this tool does is some kind of version matching (i.e. "a CVE has been reported for version x.y.z of software A, so a server running x.y.z is vulnerable"). This is a poor proxy for the actual existence of a vulnerability. It's not a "vulnerability scanner" in a sense that it actually tests for the presence of a vulnerability.
(Full disclosure: Just copied over my comment I posted on reddit earlier today)