Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn to use fuzzing tools"; now I'm saying "it's easier to just offer bounties and let someone else do the fuzzing for me".
Fuzzing is where you are going to find most memory corruption bugs these days, bounties or not.
Someone could then go and register a new Zendesk account (If the service doesn't require proof of ownership of domain), and say that they want to use the same subdomain. Now they have a Zendesk account with the URL of http://help.somedomain.com as an example. And they can phish people quite easily.
Anyway, the reason I bring it up is because for a while, I saw people spamming the shit out of bug bounties with this stuff. Because it's super simple to do.
So I'm not sure what is more lucrative for an average joe, actually learning proper techniques or trying to piggy back on some low hanging fruit that may be easy to automate.
(1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases. People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it.
(2) You are willing to get your hands dirty with shady purchasers. If you're talented, you can make good money in the grey market, or you can retain plausible deniability about what your work is being used for, but you can't do both of those things.
That first case is really the limiting factor. And remember, if you can reliably sell bugs to the grey market, that strongly implies you have lucrative options in the legitimate market. Bug bounties are not the most competitive alternative to the grey market!
That sounds like black market buyers (maybe we disagree on where the "gray" line is). Governments are very interested in bugs that allow pivoting and lateral movement.
1. If you have to ask this question, you are quite far from being able to do it any time soon (and that's assuming you can find the vulnerabilities!),
2. You will predominantly sell your vulnerabilities, preferably weaponized as complete exploits, to firms that specialize in "vulnerability research" and "exploitation development" with close ties to government agencies.
It's much easier to find a firm that can act as a broker between you and the government agency than it is to knock on the right doors to sell it on your own, with no background or prior contact.
And quite often, they will be relisted for months at a time. I'm not at all saying there's no market - we clearly know that a remote code exec on a common server will sell well.
Things like "Microsoft Word Exploit" seem a lot more like Duff beer - I'm often hearing how much they are "for sale" for a fortune but I'm not convinced people are getting the significant sums people refer to on a reliable basis.
If you are legitimately good enough, there are certainly companies out there who will pay you well and consistently to hunt for bugs/vulns.