German University Reports Severe Software Vulnerabilities Up in 2015

A German institution that maintains an online database of software vulnerabilities found that "serious" ones increased in 2015. According to Hasso Plattner Institute, while fewer software security vulnerabilities were reported worldwide in 2015 than in 2014, the number of published vulnerabilities with a high level of severity has increased. The university is concentrated on IT systems engineering, located in Potsdam.

Researchers tallied about 5,700 vulnerabilities throughout the year in HPI-VDB (the database for vulnerability analysis), compared to about 7,200 in 2014. However, while 2014 had about 1,800 weaknesses identified as "high severity," 2015 had about 2,000. However, that's still considerably down from 2008, when the database recorded a high of nearly 3,500 security flaws in software. Those assessed as medium severity dropped considerably from 2014 to 2015, while low severity vulnerabilities stayed nearly level.

The project, maintained by the IT Security Engineering Team at HPI, found that 7,000 new software products and 400 new development companies showed up in its database. The entire database stores more than 73,100 pieces of information on vulnerabilities, affecting 180,000 programs from 15,500 different software makers.

The data maintained in the HPI-VDB comes from multiple sources, primarily other publicly available Web sites with security information about vulnerabilities and security bulletins from vendors. Those include the Open Source Vulnerability Database (OSVD), Secunia, Carnegie Mellon University-run CERT, OVAL, SecurityFocus, Microsoft Security Bulletins and SAP Security Notes.

Users who register on the site are able to download information about single vulnerabilities in XML form. The researchers also make an API available for larger exports.

To protect users, HPI Director Christoph Meinel offered the same advice any security expert would: Patch software at every opportunity.

Next week the Institute will be hosting a two-week open course on maintaining privacy in social media. The MOOC is taught by computer scientist Anne Kayem and conducted in English.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • robot brain with various technology and business icons

    Google Cloud Study: Early Agentic AI Adopters See Better ROI

    Google Cloud has released its second annual ROI of AI study, finding that 52% of enterprise organizations now deploy AI agents in production environments. The comprehensive survey of 3,466 senior leaders across 24 countries highlights the emergence of a distinct group of "agentic AI early adopters" who are achieving measurably higher returns on their AI investments.

  • AI symbol racing a padlock symbol on a red running track

    AI Surpasses Cybersecurity in State Education Leader Priority List

    For the first time, artificial intelligence has moved to the top of the priority list for state education leaders — knocking cybersecurity from the number one spot, according to the 2025 State EdTech Trends report from SETDA.

  • Digital Money Bag on Circuit Board Background

    New AI Grants Program to Fund AI Infrastructure for K–12 Education

    Digital Promise has announced the launch of the K-12 AI Infrastructure Program, a multi-year initiative "aiming to close the gap between scientific principles of teaching and learning and the promise of generative artificial intelligence."

  • Red alert symbols and email icons floating in a dark digital space

    Report: Cyber Attackers Are Fully Embracing AI

    According to Google Cloud's 2026 Cybersecurity Forecast, AI will become standard for both cyber attackers and defenders, with threats expanding to virtualization systems, blockchain networks, and nation-state operations.