German University Reports Severe Software Vulnerabilities Up in 2015

A German institution that maintains an online database of software vulnerabilities found that "serious" ones increased in 2015. According to Hasso Plattner Institute, while fewer software security vulnerabilities were reported worldwide in 2015 than in 2014, the number of published vulnerabilities with a high level of severity has increased. The university is concentrated on IT systems engineering, located in Potsdam.

Researchers tallied about 5,700 vulnerabilities throughout the year in HPI-VDB (the database for vulnerability analysis), compared to about 7,200 in 2014. However, while 2014 had about 1,800 weaknesses identified as "high severity," 2015 had about 2,000. However, that's still considerably down from 2008, when the database recorded a high of nearly 3,500 security flaws in software. Those assessed as medium severity dropped considerably from 2014 to 2015, while low severity vulnerabilities stayed nearly level.

The project, maintained by the IT Security Engineering Team at HPI, found that 7,000 new software products and 400 new development companies showed up in its database. The entire database stores more than 73,100 pieces of information on vulnerabilities, affecting 180,000 programs from 15,500 different software makers.

The data maintained in the HPI-VDB comes from multiple sources, primarily other publicly available Web sites with security information about vulnerabilities and security bulletins from vendors. Those include the Open Source Vulnerability Database (OSVD), Secunia, Carnegie Mellon University-run CERT, OVAL, SecurityFocus, Microsoft Security Bulletins and SAP Security Notes.

Users who register on the site are able to download information about single vulnerabilities in XML form. The researchers also make an API available for larger exports.

To protect users, HPI Director Christoph Meinel offered the same advice any security expert would: Patch software at every opportunity.

Next week the Institute will be hosting a two-week open course on maintaining privacy in social media. The MOOC is taught by computer scientist Anne Kayem and conducted in English.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Engineering team implements digital guardrails on AI

    3 Starting Points for Integrating AI Guardrails in K-12 Districts

    As education leaders start to craft an AI policy that is both practical and flexible enough to evolve with this fast-changing technology, there is at least one principle that should be foundational: AI should serve to augment human critical thinking and creativity but never replace human interaction and decision-making.

  • abstract spiral of multi colored lights

    OpenAI's New Astra Model Reaches Critical Cyber Threshold

    OpenAI has introduced GPT-6 Astra, its most capable broadly deployed model and the first system the company says has reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.

  • abstract glowing cube outlines

    Microsoft Positions Windows as a Platform for AI Agents

    The recent Microsoft Build 2026 developer conference highlighted a significant shift in the company's Windows strategy. Rather than presenting artificial intelligence as a collection of standalone features, Microsoft is increasingly positioning Windows as an operating environment for AI agents.

  • Businessman using laptop analyzing data and growth graph chart

    Report: AI Budgets in Education Show No Sign of Decline

    The vast majority of education organizations (98%) expect their AI infrastructure budgets to either increase or hold steady over the next year, according to a report from cloud storage provider Wasabi.