Server vulnerability scanning

How can I discover server vulnerabilities without using a scanning software such as openVas? is there any manual ways or steps to follow to assure server security. Thanks in advance
Is it recommended to patch announced vulnerability for unused services or features?

Sometimes vendors announce software upgrade to patch some discovered vulnerability in some feature or service which is not enabled in your system. Is it recommended to upgrade your software although you are theoretically not affected by?
Are CVE identifiers assigned for proprietary software packages?

If I find a vulnerability while using a proprietary software package can I request a CVE identifier. Or rather vulnerabilities in proprietary software packages are a matter of me reporting issue to vendor and vendor looking into it?
Where can I find real life examples of software vulnerabilities in OSS?

I am looking for a repository of real life vulnerabilities (in this specific situation, buffer overflows in C & C++) that have been detected in open source software. Ideally it would show exactly where in the code the vulnerabilities have occurred…
Which database is used by npm-audit

you probably know the npm-audit tool which informs you about vulns in your node.js projects dependencies. I'd like to know what database npm-audit is using and how I get access to this data. Thank you :)
Can browser emulation create vulnerabilities?

If a browser is not authorized on a network, can browser emulation within an authorized browser create vulnerabilities? For instance, Chrome is unauthorized but if I run IE, press F12 to get into Developer mode, and then have it emulate Chrome, will…
Why is MITRE not changing CVE entries that are clearly incorrect?

Why is MITRE not changing some CVE entries that are clearly wrong? I have deeply analysed and highly tested some specific vulnerabilities. The CVE reports of them are in some cases inconsistent, incorrect or even registered to one CPE while I…
