German University Says Severe Software Vulnerabilities Up in 2015

A German institution that maintains an online database of software vulnerabilities found that the count for "serious" ones increased in 2015. According to Hasso Plattner Institute, while fewer software security vulnerabilities were reported worldwide in 2015 than in 2014, the number of published vulnerabilities with a high level of severity has increased. The university is concentrated on IT systems engineering, located in Potsdam.

Researchers tallied about 5,700 vulnerabilities throughout the year in HPI-VDB (the database for vulnerability analysis), compared to about 7,200 in 2014. However, while 2014 had about 1,800 weaknesses identified as "high severity," 2015 had about 2,000. However, that's still considerably down from 2008, when the database recorded a high of nearly 3,500 security flaws in software. Those assessed as medium severity dropped considerably from 2014 to 2015, while low severity vulnerabilities stayed nearly level.

The project, maintained by the IT Security Engineering Team at HPI, found that 7,000 new software products and 400 new development companies showed up in its database. The entire database stores more than 73,100 pieces of information on vulnerabilities, affecting 180,000 programs from 15,500 different software makers.

The data maintained in the HPI-VDB comes from multiple sources, primarily other publicly available Web sites with security information about vulnerabilities and security bulletins from vendors. Those include the Open Source Vulnerability Database (OSVD), Secunia, Carnegie Mellon University-run CERT, OVAL, SecurityFocus, Microsoft Security Bulletins and SAP Security Notes.

Users who register on the site are able to download information about single vulnerabilities in XML form. The researchers also make an API available for larger exports.

To protect users, HPI Director Christoph Meinel offered the same advice any security expert would: Patch software at every opportunity.

Next week the Institute will be hosting a two-week open course on maintaining privacy in social media. The MOOC is taught by computer scientist Anne Kayem and conducted in English.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • abstract glowing cube outlines

    Microsoft Positions Windows as an Operating Environment for AI Agents

    The recent Microsoft Build 2026 developer conference highlighted a significant shift in the company's Windows strategy. Rather than presenting artificial intelligence as a collection of standalone features, Microsoft is increasingly positioning Windows as a platform for AI agents.

  • abstract smartphone translucent screen displaying AI interface

    Apple Introduces Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple introduced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.

  • user typing login and password

    Report: Attackers Now Focus on Credential Theft to Access Systems

    Hackers are shifting their focus from "breaking in" to "logging in," according to the 2026 Cloudflare Threat Report.

  • robot hand holding stacks of coins

    Designing AI Systems for Financial Aid

    Financial aid offices have been slow to adopt AI, risking technological stagnation at a critical early student touchpoint. Systematic AI integration can improve student experiences and strengthen institutional positioning.