Eh, it just seems to compare detected versions against the latest version of software. It would be nice if it said why the installed version is vulnerable, links to CVEs, etc.
For now we spend more time into giving information on how to keep your system secure and make that as easy as possible. If we can present 1 solution to fix 22 cve exploits, we find that preferable to showing 22 issues that need to get fixed with detailed information about the cve. But should that data should still be findable for experts and is also shown our the data cards. (Except when the data isn't disclosed yet by the software manufacturer) So if you don't see the CVE, please tell us more details about the software that doesn't has vulnerabilities.