Right. There are a few projects that can be generally trusted with internet exposure - like OpenSSH, Wireguard, nginx/Apache. Most other stuff should be kept behind some kind of firewall because it is just too likely to contain a serious vulnerability.