Wasn't CVE-2020-15999 a bug in Freetype, which Firefox also uses? Why isn't there a Firefox CVE on the list from the same time? Was the bug not exploitable in Firefox for some reason, or is this list just incomplete?
(Never mind that comparing counts of CVEs is a ridiculous way to compare security of products. CVE counts seem more indicative of the amount of research targeting the product than of the number of bugs in the product.)