I'm like 99% sure they intentionally left a few 'low-risk' vulnerabilities which they knew people would uncover (and be rewarded for) to entice the big boys of security probing to roll up their sleeves and get to work looking for the really big ones.
In the long run, they're paying a reasonable amount of money for an army of security consultants to give the service a once-over. Smart!