A full node can run without accepting connections: it connects out to peers, validates every block and serves its owner. Only a node that listens for incoming connections, at an address others can reach, can be found and counted from outside.
Crawlers such as the one run by KIT's Decentralized Systems and Network Services group connect to every address they learn about and record what each node announces in its handshake: its protocol version, its user agent, the services it offers. Their totals are counts of reachable nodes at a moment, and they differ with the crawler, the networks it covers and how recently a node must have answered to be counted.
A reachable-node count is a population measured by a stated method, never the number of nodes.