That's an extremely broad question and it's not a simple topic to get information on because not a lot of people are going to answer to be frank.
I will say though a great place to start is by going on and watching some Intigriti videos or other bug bounty sort of tutorials. Follow along and learn how different vulnerabilities are found and exploited.
Learn how things actually work on the back end, and start browsing around looking for things that seem like they might be vulnerable.
The more you do this, the more you learn, the easier it will become and the more likely you are to actually find some worthwhile vulnerabilities.
It's not always as simple as just running a script on a site you have in mind as a target.
Best thing you can do is just get started and keep at it!