Sorry to say, but that's kind of stupid question. As one can fuck up security of each product on it's own, it's hard to say. PVE comes secure ootb and you can increase security by adding more layers like specific firewall rules, fail2ban.
If you refer to the hypervisor itself, you should search the web for KVM and security. Also hardening Debian should reveal some information.