We run our B2B order management system on a single virtual server. The database, web app, and mail queue all live on the same machine. Out of curiosity the other night, I ran an Nmap vulnerability scan against my own server via the command line. Besides ports 22 80, and 443, I saw that ports 3306 and 8080 were open too. On top of that, the script output listed a few CVE IDs and potential risk warnings highlighted in red.
My technical knowledge is enough to manage a server but I'm no security expert. Do these CVE warnings mean my system is actively exploitable right this second, or do these tools just blow things out of proportion with generic warnings? How should I filter these results to read them properly and at what point do I actually need to hire out a professional penetration test?