Yes, the vulnerabilities are kept secret. The value of an exploit decreases significantly after the vulnerability is patched, and they are in the business of selling high value exploits. If they couldn't sell the exploits, they wouldn't be finding the vulnerabilities either. Banning exploit sales won't suddenly result in VUPEN turning into a vuln finding charity.
For whatever it's worth, zeroday exploits are rare in practice. The vast majority of exploited systems are taken down with public vulns because they weren't patched in time. Very few organizations are interested in specific targets; carpet bombing the internet and searching for unpatched shellshock/drupal/etc installations will collect enough low hanging fruit.