In order for your Poloniex account to be compromised with this security, the attacker would need to either:
-Compromise the passwords of both Poloniex and your email provider;
-Brute force your passwords using a computer (possible if you use a weak password);
-Infect your computer with malware such as a keylogger.
If you add 2fa, the attacker needs to do the same things as before, but also find and reach your physical location.
Unless there's a problem with 2fa,
that's how you stay safe. The majority of attackers will act just online.
I often received a one time pin code through my email anytime i try to log in to my poloniex account and i must confirm my access using this codes but is this enough a security ? Can it not be broken easily?
As long as your email address has a completely different password to your Poloniex account, it's pretty safe.
Malware from dodgy BTC sites is common when BTC is such an appealing thing to steal. Be careful.