And this is why the numbers are so high -- because all of those "vulnerability reports" are complete junk most of the time. SSHD warnings for systems which do not run sshd. ImageMagick vulnerabilities for internal code docs generator. A high severity sudo vulnerability which requires a specific very uncommon configuration.
A great idea on paper, but it is achieving an opposite effect, teaching people that most of automated vulnerability detections are junk.