Except virtual box is open source and probably the whole reason these vulnerabilities are found. I’m sure similar vulnerabilities could exist in VMware but are much harder to find due to being closed source.
In my experience of casual usage VMware is less buggy in general (no random crashes, etc.), and that usually translates into fewer security bugs too.
But if your adversary is spending $$$$$ on vulns to throw at you, you can probably assume they can vm-escape either one.
https://www.blackhat.com/presentations/bh-usa-09/KORTCHINSKY...
https://www.darkreading.com/vulnerabilities-threats/vmware-z...
https://cloud.google.com/blog/topics/threat-intelligence/vmw...