On Windows, there is Hyper-V. I have only very little experience with it, but in my short time, I did not encounter anything I would like to complain about. I am not sure, however, if it comes with the client editions of Windows. Microsoft Virtual PC still exists, too.
Xen is also a thing - run Dom0 as your desktop system, and run the VMs in the background.
None of this is perfect, but if you need them, there are alternatives.
Not updated in almost 10 years, not supported on Windows 8 or 10.
It's in Windows 10 client editions too. Look under "Turn Windows features on or off". Windows Subsystem for Linux is there too.
AWS recently started moving from a custom Xen to a custom KVM, but it doesn't seem it was for security reasons. Xen certainly is heavily used by public cloud providers.
Because of its use with KVM, QEMU has had its code scrutinized quite closely in the last few years. There are some device models that have a pretty bad track record, such as Cirrus VGA, but they are not the default anymore and there's no reason why you should use them.
Any other hypervisor. QEMU/KVM, Xen, VMWare, and Parallels all have good track records.
This skews the CVE stats significantly since the kernel developers (aka kvm) rarely actually request CVE ids.
This also holds true for the alternatives.
https://www.cvedetails.com/vulnerability-list/vendor_id-2505...
Better than this though:
https://www.cvedetails.com/vulnerability-list/vendor_id-93/p...
This is particularly important when KVM is used with a special user (such as user "qemu") and SELinux, because then a bug in QEMU becomes extremely hard to turn into host root access. Libvirt takes care of configuring SELinux this way for you, when you use for example KVM on OpenStack.
VirtualBox also has a slicker UI compared with QEMU/KVM on linux & bhyve on FreeBSD/Mac & vmm on OpenBSD.
The alternatives all have their own merits, but if people are wondering why anyone would use VirtualBox, I believe the above reasons are why.