ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65791.json"