I would recommend that you prioritize first, and then decide how to handle the rest.
First, change the passwords of all of the accounts that could cause you significant harm if taken over (e.g. email accounts, financial accounts, retirement accounts, government accounts, cloud storage accounts, etc.). While you are at it, make sure that you are using password best practices for each new password:
- Length is very important, so at least 14 characters
- Use a unique password for every account (reusing passwords is likely what got you into this mess)
- Unguessable (don't use patterns or any information that would be known from social media)
- For any significant account you may need to remember without the use of your password manager (such as if you lost your phone when on travel), use a strong but easy to remember passphrase
- For all other accounts you can use a completely random password because your password manager will fill it for you.
- Always enable multi-factor authentication and take the time needed to store MFA/2FA recovery codes and information carefully (such as in password protected Notes).
- Establish passkeys where available
Then, over time, work to change your less important accounts, never reusing a password.