Looking at the software quality produced by large teams, I have serious doubts if bigger means better. If M$ publishes an OS simulator with more than 600 security-relevant bugs in 1 year, that indicates lousy software quality. On the other hand, there are lots of software products, especially in the FOSS area, that are produced by small teams and are excellent with respect to functionality and security.
With respect to the security of Qubes, we must distinguish between “normal” bugs affecting only functionality, on the one hand, and security-relevant bugs that undermine compartmentalization, on the other. The effects of normal bugs, even indom0, are restricted to some VM, while security-relevant bugs allow the breakout out of this VM. Due to the Xen architecture, any bug in a VM, except for `dom0, will not allow such a breakout. (This is even confirmed by AI - I checked with ChatGPT.)
To escape from a VM, you will need a security hole in Xen itself, and Xen is supported very carefully and outside of Qubes, because any compromise of its security will endanger some of the largest clouds. It is not impossible that 0days might exist in Xen, but they are surely not available on the common black market, because they have an immense value for an attacker.
So, Qubes is secure against attacks of “normal” hackers as long as dom0 is not compromised, and all available fixes are installed for Xen.
The situation is different, however, if we talk about attackers with unlimited resources, possibly state-sponsored, who are able to subvert Xen. But then you have to ask yourself if you are important enough to get into their focus, which will not apply to most users, because these super-hackers will not attack unimportant targets, since that would reveal their own secrets.
But if you have to protect yourself from such attacks, you should not rely on any available software - including software that you yourself have created. Stay completely offline, without any network connection, and maybe even consider emigrating to a more secure location. You might consider the Heard and McDonald islands - their inhabitants are Linux-friendly and known never to have hacked IT systems. 