Why don't they?
People pay for vulnerabilities because they want to exploit them - if there’s a limited window, there’s limited demand.
Even if there’s something worth a lot behind the exploit, a potential criminal would be better off obtaining whatever that is and selling it instead.
I don't think the other commenters mentioning how server-side vulnerabilities aren't as lucrative in the black market are making that connection.